CVE-2023-38403

CWE-190Integer Overflow13 documents9 sources
Severity
7.5HIGH
EPSS
1.3%
top 20.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17
Latest updateOct 25

Description

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDes/iperf3< 3.14
Debianiperf3< 3.9-1+deb11u1+3
Ubuntuiperf3< 3.9-1+deb11u1build0.22.04.1+3
NVDapple/macos< 13.6.1+1

Also affects: Debian Linux 10.0, Fedora 37, 38

Patches

🔴Vulnerability Details

5
OSV
iperf3 vulnerabilities2023-10-16
OSV
iperf3 vulnerability2023-10-16
OSV
CVE-2023-38403: iperf3 before 32023-07-17
GHSA
GHSA-hgwq-wchh-f9vv: iperf3 before 32023-07-17
CVEList
CVE-2023-38403: iperf3 before 32023-07-17

📋Vendor Advisories

7
Apple
CVE-2023-38403: macOS Sonoma 14.12023-10-25
Apple
CVE-2023-38403: macOS Ventura 13.6.12023-10-25
Ubuntu
iperf3 vulnerability2023-10-16
Ubuntu
iperf3 vulnerabilities2023-10-16
Red Hat
iperf3: memory allocation hazard and crash2023-07-11
CVE-2023-38403 (HIGH CVSS 7.5) | iperf3 before 3.14 allows peers to | cvebase.io