Integer Overflow or Wraparound Affecting iperf3 package, versions <0:3.9-10.el9_2.alma
Threat Intelligence
EPSS
0.54% (78th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ALMALINUX9-IPERF3-5836216
- published 9 Aug 2023
- disclosed 8 Aug 2023
Introduced: 8 Aug 2023
CVE-2023-38403 Open this link in a new tabHow to fix?
Upgrade AlmaLinux:9
iperf3
to version 0:3.9-10.el9_2.alma or higher.
This issue was patched in ALSA-2023:4571
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream iperf3
package and not the iperf3
package as distributed by AlmaLinux
.
See How to fix?
for AlmaLinux:9
relevant fixed versions and status.
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
References
- https://errata.almalinux.org/8/ALSA-2023-4570.html
- https://errata.almalinux.org/9/ALSA-2023-4571.html
- https://access.redhat.com/security/cve/CVE-2023-38403
- https://access.redhat.com/errata/RHSA-2023:4570
- https://access.redhat.com/errata/RHSA-2023:4571
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BV6EBWWF4PEQKROEVXGYSTIT2MGBTLU7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M25Z5FHTO3XWMGP37JHJ7IIIHSGCLKEV/
- http://seclists.org/fulldisclosure/2023/Oct/24
- http://seclists.org/fulldisclosure/2023/Oct/26
- https://bugs.debian.org/1040830
- https://cwe.mitre.org/data/definitions/130.html
- https://downloads.es.net/pub/iperf/esnet-secadv-2023-0001.txt.asc
- https://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9
- https://github.com/esnet/iperf/issues/1542
- https://lists.debian.org/debian-lts-announce/2023/07/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BV6EBWWF4PEQKROEVXGYSTIT2MGBTLU7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M25Z5FHTO3XWMGP37JHJ7IIIHSGCLKEV/
- https://security.netapp.com/advisory/ntap-20230818-0016/
- https://support.apple.com/kb/HT213984
- https://support.apple.com/kb/HT213985
CVSS Scores
version 3.1