CVE-2019-14850

CWE-4069 documents7 sources
Severity
3.7LOW
EPSS
0.3%
top 46.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 24

Description

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4

Affected Packages5 packages

NVDnbdkit_project/nbdkit1.14.01.14.1+2
Debiannbdkit< 1.14.1-1+3
CVEListV5nbdkitnbdkit 1.12.7, nbdkit 1.14.1, nbdkit 1.15.1

Also affects: Enterprise Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-j552-f62v-mc74: A denial of service vulnerability was discovered in nbdkit 12022-05-24
CVEList
CVE-2019-14850: A denial of service vulnerability was discovered in nbdkit 12021-03-18
OSV
CVE-2019-14850: A denial of service vulnerability was discovered in nbdkit 12021-03-18

📋Vendor Advisories

2
Red Hat
nbdkit: denial of service due to premature opening of back-end connection2019-09-20
Debian
CVE-2019-14850: nbdkit - A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1....2019

💬Community

3
Bugzilla
CVE-2019-14850 nbdkit: denial of service due to premature opening of back-end connection [epel-7]2019-10-01
Bugzilla
CVE-2019-14850 nbdkit: denial of service due to premature opening of back-end connection [fedora-all]2019-10-01
Bugzilla
CVE-2019-14850 nbdkit: denial of service due to premature opening of back-end connection2019-10-01
CVE-2019-14850 (LOW CVSS 3.7) | A denial of service vulnerability w | cvebase.io