SB2023072650 - Denial of service in iperf
Published: July 26, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2023-38403)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow. A remote attacker can pass specially crafted length field to the application, trigger an integer overflow and perform a denial of service (DoS0 attack.
Remediation
Install update from vendor's website.
References
- https://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9
- https://bugs.debian.org/1040830
- https://github.com/esnet/iperf/issues/1542
- https://downloads.es.net/pub/iperf/esnet-secadv-2023-0001.txt.asc
- https://cwe.mitre.org/data/definitions/130.html
- https://lists.debian.org/debian-lts-announce/2023/07/msg00025.html