cbcvebase.
CVE-2023-38403
published 2023-07-17

CVE-2023-38403: iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

Affected

21 ranges
VendorProductVersion rangeFixed in
applemacos< 13.6.113.6.1
applemacos
applemacos_sonoma
applemacos_ventura
debiandebian_linux
debianiperf3< iperf3 3.12-1+deb12u1 (bookworm)iperf3 3.12-1+deb12u1 (bookworm)
esiperf3< 3.143.14
esiperf3>= 0 < 3.9-1+deb11u13.9-1+deb11u1
esiperf3>= 0 < 3.12-1+deb12u13.12-1+deb12u1
esiperf3>= 0 < 3.14-13.14-1
esiperf3>= 0 < 3.14-13.14-1
esiperf3>= 0 < 3.9-1+deb11u1build0.22.04.13.9-1+deb11u1build0.22.04.1
esiperf3>= 0 < 3.0.11-1ubuntu0.1~esm23.0.11-1ubuntu0.1~esm2
esiperf3>= 0 < 3.1.3-1ubuntu0.1~esm13.1.3-1ubuntu0.1~esm1
esiperf3>= 0 < 3.7-3ubuntu0.1~esm13.7-3ubuntu0.1~esm1
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_iperf3_3.14-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
netappclustered_data_ontap

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH