cbcvebase.
CVE-2019-14850
published 2021-03-18

CVE-2019-14850: A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a…

PriorityP414low3.7CVSS 3.1
AVNACHPRNUINSUCNINAL
EPSS
1.60%
73.1th percentile
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiannbdkit< nbdkit 1.14.1-1 (bookworm)nbdkit 1.14.1-1 (bookworm)
nbdkit_projectnbdkit< 1.12.71.12.7
nbdkit_projectnbdkit
nbdkit_projectnbdkit>= 0 < 1.14.1-11.14.1-1
nbdkit_projectnbdkit>= 0 < 1.14.1-11.14.1-1
nbdkit_projectnbdkit>= 0 < 1.14.1-11.14.1-1
nbdkit_projectnbdkit>= 0 < 1.14.1-11.14.1-1
nbdkit_projectnbdkit>= 1.14.0 < 1.14.11.14.1
nbdkit_projectnbdkit>= 1.15.0 < 1.15.11.15.1
redhatenterprise_linux
redhatenterprise_linux_server
redhatvirtualization

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.