The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-updates/2015-06/msg00003.html - | |
References | () http://sourceforge.net/p/nbd/mailman/message/30410146/ - | |
References | () http://www.debian.org/security/2015/dsa-3271 - | |
References | () http://www.openwall.com/lists/oss-security/2015/05/19/6 - | |
References | () http://www.openwall.com/lists/oss-security/2015/05/21/5 - | |
References | () http://www.securityfocus.com/bid/74808 - | |
References | () http://www.ubuntu.com/usn/USN-2676-1 - | |
References | () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781547 - | |
References | () https://github.com/yoe/nbd/commit/741495cb08503fd32a9d22648e63b64390c601f4 - |
Information
Published : 2015-05-29 15:59
Updated : 2024-11-21 02:01
NVD link : CVE-2013-7441
Mitre link : CVE-2013-7441
CVE.ORG link : CVE-2013-7441
JSON object : View
Products Affected
wouter_verhelst
- nbd
CWE
CWE-399
Resource Management Errors