VulnerabilityModified
CVE-2019-14850
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1.
LOW 3.7EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.
- CVSS 3.1
- 3.7 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-406
- Affected
- nbdkit project/nbdkit · redhat/virtualization · redhat/enterprise linux · redhat/enterprise linux server
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1757258Issue Tracking, Patch, Third Party Advisory
- https://www.redhat.com/archives/libguestfs/2019-September/msg00084.htmlExploit, Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1757258Issue Tracking, Patch, Third Party Advisory
- https://www.redhat.com/archives/libguestfs/2019-September/msg00084.htmlExploit, Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.