SB2024080868 - MitM attack in libnbd
Published: August 8, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Certificate Validation (CVE-ID: CVE-2024-7383)
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exist due to improper certificate validation when handling the NBD server's certificate. A remote attacker can perform MitM attack.
Remediation
Install update from vendor's website.
References
- https://access.redhat.com/security/cve/CVE-2024-7383
- https://bugzilla.redhat.com/show_bug.cgi?id=2302865
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/message/LHR3BW6RJ7K4BJBQIYV3GTZLSY27VZO2
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/ENZY4LHLARA3N4C3JUNLPYUCXHFO7BWQ/