PT-2015-3589 · Nbd+2 · Nbd-Server+2
Tuomas Räsänen
·
Published
2015-05-23
·
Updated
2024-11-15
·
CVE-2013-7441
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
nbd-server versions 2.9.22 through 3.3
Description
The issue in nbd-server allows remote attackers to cause a denial of service by either closing the connection during negotiation or specifying a name for a non-existent export, which can lead to the termination of the root process.
Recommendations
For versions 2.9.22 through 3.3, consider implementing measures to handle connection closures and invalid export names to prevent denial of service attacks. As a temporary workaround, restrict access to the nbd-server to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ubuntu
Nbd-Server