Monday, October 16, 2023

[USN-6431-1] iperf3 vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEKQtTo2MNG44yJq/lXjZQcrWpV2YFAmUtPcYFAwAAAAAACgkQXjZQcrWpV2ZA
kBAAj3WGrbvakgH+w9H6aYOgYerrn2pITvGa3dApUQEhxFZlbgV+aVsTqvBka/G0SXd9abzBZkrc
vsNX6bNaK/BHS9hZwZNiPlFVLKD9nO3+SMJ0SB+MbjSKWZHqGRXOqrq+KBH9mdO+fj24hIWfxdbg
Oo1Qj2LHwsnVB0w6/3BSiJq7F7pX8wznc9nTfSYDCC789LG1Z5rmzAOyzQOyjDSGq7MYQB3wi75g
BCL2+5ImZ0WLzGACAN4DaBKQHaM+XcjPnqEMhokAe+/C8rbgj5OI3sWEdEMKdzCak4bRNUDedkRQ
9Xb0J8YvFRhJAMiAo7RsiqLsKKh8bTFs/43LP0bxOxpgJxMLG3Eshs69c6LhUx6xiXA4gvu46B3d
jtYJ9FvinYnIuy5DiD26HjDI8smd1VZj5HIsKHKOM8noHhSm6YzF6oOPuyIutuaSULbjLeH1+Ray
RzPLJLW/hiz00WqnCPWecdYXuiu/IIBnS7LkeI6Ke2Zp1oLbdXGdVmBpokRGWmV8YjM7m9qfeKHY
xospZz71hU9kk6f2waqCogOnH2RGnKKkZOlj5B2lHffLcZHgDnTVs5IFDH1nRrAMqN9tef9GyrbF
OTu154IxQQL+ztGKgnmbGb6Q/XSdP7RNCG3ew+JvbDt2PRxBTl9EkJjw6Ycxw7bakP0/cwNa+NSi
nU0=
=7lHT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6431-1
October 16, 2023

iperf3 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS (Available with Ubuntu Pro)
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)

Summary:

Several security issues were fixed in iperf3.

Software Description:
- iperf3: Internet Protocol bandwidth measuring tool

Details:

It was discovered that iperf3 did not properly manage certain inputs,
which could lead to a crash. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38403)

Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. (LP: #2038654)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS (Available with Ubuntu Pro):
  iperf3                          3.7-3ubuntu0.1~esm1
  libiperf0                       3.7-3ubuntu0.1~esm1

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
  iperf3                          3.1.3-1ubuntu0.1~esm1
  libiperf0                       3.1.3-1ubuntu0.1~esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
  iperf3                          3.0.11-1ubuntu0.1~esm2
  libiperf0                       3.0.11-1ubuntu0.1~esm2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6431-1
  CVE-2023-38403, https://launchpad.net/bugs/2038654

No comments:

Post a Comment