CVE-2023-38403
published 2023-07-17CVE-2023-38403: iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.70%
74.6th percentile
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 13.6.1 | 13.6.1 |
| apple | macos | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| debian | debian_linux | — | — |
| debian | iperf3 | < iperf3 3.12-1+deb12u1 (bookworm) | iperf3 3.12-1+deb12u1 (bookworm) |
| es | iperf3 | < 3.14 | 3.14 |
| es | iperf3 | >= 0 < 3.9-1+deb11u1 | 3.9-1+deb11u1 |
| es | iperf3 | >= 0 < 3.12-1+deb12u1 | 3.12-1+deb12u1 |
| es | iperf3 | >= 0 < 3.14-1 | 3.14-1 |
| es | iperf3 | >= 0 < 3.14-1 | 3.14-1 |
| es | iperf3 | >= 0 < 3.9-1+deb11u1build0.22.04.1 | 3.9-1+deb11u1build0.22.04.1 |
| es | iperf3 | >= 0 < 3.0.11-1ubuntu0.1~esm2 | 3.0.11-1ubuntu0.1~esm2 |
| es | iperf3 | >= 0 < 3.1.3-1ubuntu0.1~esm1 | 3.1.3-1ubuntu0.1~esm1 |
| es | iperf3 | >= 0 < 3.7-3ubuntu0.1~esm1 | 3.7-3ubuntu0.1~esm1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_iperf3_3.14-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| netapp | clustered_data_ontap | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-38403: macOS Sonoma 14.1
vendor_apple·2023-10-25·CVSS 7.5
CVE-2023-38403 [HIGH] CVE-2023-38403: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-38403
Component: CVE-2023-38403
Apple
CVE-2023-38403: macOS Ventura 13.6.1
vendor_apple·2023-10-25·CVSS 7.5
CVE-2023-38403 [HIGH] CVE-2023-38403: macOS Ventura 13.6.1
Apple Security Update: About the security content of macOS Ventura 13.6.1
Product: macOS Ventura
Version: 13.6.1
CVE: CVE-2023-38403
Component: CVE-2023-38403
Ubuntu
iperf3 vulnerability
vendor_ubuntu·2023-10-16·CVSS 7.5
CVE-2023-38403 [HIGH] iperf3 vulnerability
Title: iperf3 vulnerability
Summary: iperf3 could be made to crash if it received specially crafted network
traffic.
USN-6431-1 fixed a vulnerability in iperf3. This update provides
the corresponding update for Ubuntu 22.04 LTS and Ubuntu 23.04.
Original advisory details:
It was discovered that iperf3 did not properly manage certain inputs,
which could lead to a crash. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38403)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
iperf3 vulnerabilities
vendor_ubuntu·2023-10-16·CVSS 7.5
CVE-2023-38403 [HIGH] iperf3 vulnerabilities
Title: iperf3 vulnerabilities
Summary: Several security issues were fixed in iperf3.
It was discovered that iperf3 did not properly manage certain inputs,
which could lead to a crash. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38403)
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. (LP: #2038654)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
iperf3: memory allocation hazard and crash
vendor_redhat·2023-07-11·CVSS 7.5
CVE-2023-38403 [HIGH] CWE-190 iperf3: memory allocation hazard and crash
iperf3: memory allocation hazard and crash
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
An integer overflow flaw was found in the way iperf3 dynamically allocates memory buffers for JSON-formatted messages. A remote attacker could send a specially crafted sequence of bytes on the iperf3 control channel with a specified JSON message length of 0xffffffff to trigger an integer overflow leading the receiving process to abort due to heap corruption. This flaw allows an attacker to use a malicious client to cause a denial of service of an iperf3 server or potentially use a malicious server to cause connecting clients to crash.
Statement: The most common usage of iperf3 is temporary and between trusted devices on private networks.
Microsoft
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
vendor_msrc·2023-07-11·CVSS 7.5
CVE-2023-38403 [HIGH] CWE-190 iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remedi
Debian
CVE-2023-38403: iperf3 - iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption...
vendor_debian·2023·CVSS 7.5
CVE-2023-38403 [HIGH] CVE-2023-38403: iperf3 - iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption...
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
Scope: local
bookworm: resolved (fixed in 3.12-1+deb12u1)
bullseye: resolved (fixed in 3.9-1+deb11u1)
forky: resolved (fixed in 3.14-1)
sid: resolved (fixed in 3.14-1)
trixie: resolved (fixed in 3.14-1)
OSV
iperf3 vulnerabilities
osv·2023-10-16·CVSS 7.5
CVE-2023-38403 [HIGH] iperf3 vulnerabilities
iperf3 vulnerabilities
It was discovered that iperf3 did not properly manage certain inputs,
which could lead to a crash. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38403)
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. (LP: #2038654)
OSV
iperf3 vulnerability
osv·2023-10-16·CVSS 7.5
CVE-2023-38403 [HIGH] iperf3 vulnerability
iperf3 vulnerability
USN-6431-1 fixed a vulnerability in iperf3. This update provides
the corresponding update for Ubuntu 22.04 LTS and Ubuntu 23.04.
Original advisory details:
It was discovered that iperf3 did not properly manage certain inputs,
which could lead to a crash. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38403)
OSV
CVE-2023-38403: iperf3 before 3
osv·2023-07-17·CVSS 7.5
CVE-2023-38403 [HIGH] CVE-2023-38403: iperf3 before 3
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
GHSA
GHSA-hgwq-wchh-f9vv: iperf3 before 3
ghsa_unreviewed·2023-07-17
CVE-2023-38403 [HIGH] CWE-190 GHSA-hgwq-wchh-f9vv: iperf3 before 3
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2023/Oct/24http://seclists.org/fulldisclosure/2023/Oct/26https://bugs.debian.org/1040830https://cwe.mitre.org/data/definitions/130.htmlhttps://downloads.es.net/pub/iperf/esnet-secadv-2023-0001.txt.aschttps://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9https://github.com/esnet/iperf/issues/1542https://lists.debian.org/debian-lts-announce/2023/07/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BV6EBWWF4PEQKROEVXGYSTIT2MGBTLU7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M25Z5FHTO3XWMGP37JHJ7IIIHSGCLKEV/https://security.netapp.com/advisory/ntap-20230818-0016/https://support.apple.com/kb/HT213984https://support.apple.com/kb/HT213985http://seclists.org/fulldisclosure/2023/Oct/24http://seclists.org/fulldisclosure/2023/Oct/26https://bugs.debian.org/1040830https://cwe.mitre.org/data/definitions/130.htmlhttps://downloads.es.net/pub/iperf/esnet-secadv-2023-0001.txt.aschttps://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9https://github.com/esnet/iperf/issues/1542https://lists.debian.org/debian-lts-announce/2023/07/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BV6EBWWF4PEQKROEVXGYSTIT2MGBTLU7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M25Z5FHTO3XWMGP37JHJ7IIIHSGCLKEV/https://security.netapp.com/advisory/ntap-20230818-0016/https://support.apple.com/kb/HT213984https://support.apple.com/kb/HT213985
2023-07-17
Published