CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2017-7401 Amazon Linux Security Advisory for collectd: ALAS-2017-829

2017年5月20日 1416点热度 0人点赞 0条评论

漏洞类别:Amazon Linux

漏洞等级:

漏洞信息

Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions:
Collectd contains an infinite loop due to how the parse_packet() and parse_part_sign_sha256() functions interact. If an instance of collectd is configured with "SecurityLevel None" and with empty "AuthFile" options an attacker can send crafted UDP packets that trigger the infinite loop, causing a denial of service. (CVE-2017-7401 )

QID Detection Logic (Authenticated):
We check for file versions less than 5.7.1-3.18.amzn1 for the following files: collectd-memcachec, collectd-curl_xml, collectd-bind, collectd-lua, collectd-java, collectd-snmp, collectd-write_sensu, collectd-dns, libcollectdclient, collectd-apache, collectd-ipmi, collectd-lvm, collectd-chrony, collectd-mysql, collectd-nginx, collectd-netlink, collectd-varnish, collectd-amqp, collectd-iptables, perl-Collectd, collectd-drbd, collectd-python, collectd-generic-jmx, collectd-email, collectd-postgresql, collectd, collectd-write_http, collectd-web, collectd-debuginfo, collectd-dbi, collectd-openldap, collectd-rrdcached, collectd-notify_email, libcollectdclient-devel, collectd-zookeeper, collectd-rrdtool, collectd-utils, collectd-write_tsdb, collectd-curl, collectd-ipvs, collectd-hugepages, collectd-gmond,

漏洞危害

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

解决方案

Please refer to Amazon advisory ALAS-2017-829 for affected packages and patching details, or update with your package manager.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

ALAS-2017-829: Amazon Linux (collectd (5.7.1-3.18.amzn1) on i686)

ALAS-2017-829: Amazon Linux (collectd (5.7.1-3.18.amzn1) on x86_64)

ALAS-2017-829: Amazon Linux (collectd (5.7.1-3.18.amzn1) on src)

0day

标签: 暂无
最后更新:2017年5月20日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me