CVE-2023-4785 Affecting libgrpc37 package, versions <1.60.0-150400.8.3.2


Severity

Recommended
0.0
high
0
10

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.11% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES155-LIBGRPC37-6261776
  • published22 Feb 2024
  • disclosed21 Feb 2024

Introduced: 21 Feb 2024

CVE-2023-4785  (opens in a new tab)

How to fix?

Upgrade SLES:15.5 libgrpc37 to version 1.60.0-150400.8.3.2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libgrpc37 package and not the libgrpc37 package as distributed by SLES. See How to fix? for SLES:15.5 relevant fixed versions and status.

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

CVSS Scores

version 3.1