CVE-2017-7401Infinite Loop in Collectd

CWE-835Infinite Loop12 documents7 sources
Severity
7.5HIGHNVD
OSV9.1
EPSS
1.0%
top 23.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3
Latest updateMay 13

Description

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/collectd< collectd 5.7.2-1 (bookworm)
Debiancollectd/collectd< 5.7.2-1+3
Ubuntucollectd/collectd< 5.4.0-3ubuntu2.2+esm1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3f98-9h78-w5jh: Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network2022-05-13
OSV
collectd vulnerabilities2021-03-15
OSV
CVE-2017-7401: Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network2017-04-03

📋Vendor Advisories

3
Ubuntu
collectd vulnerabilities2021-03-15
Red Hat
collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions2017-02-13
Debian
CVE-2017-7401: collectd - Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functio...2017

💬Community

5
Bugzilla
CVE-2017-7401 collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions [epel-6]2017-04-06
Bugzilla
CVE-2017-7401 collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions [epel-7]2017-04-06
Bugzilla
CVE-2017-7401 collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions2017-04-06
Bugzilla
CVE-2017-7401 puppet-collectd: collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions [openstack-rdo]2017-04-06
Bugzilla
CVE-2017-7401 collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions [fedora-all]2017-04-06