SUSE-SU-2017:1365-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1365-1
SUSE-SU-2017:1365-1
Summary: Security update for collectd
Details: This update for collectd fixes one issue. This security issue was fixed: - CVE-2017-7401: Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c allowed remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with 'SecurityLevel None' and with empty 'AuthFile' options) via a crafted UDP packet (bsc#1032307).
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171365-1/, https://bugzilla.suse.com/1032307, https://www.suse.com/security/cve/CVE-2017-7401
Affected packages
Package
Name: collectd
Purl: pkg:rpm/suse/collectd&distro=SUSE%20Lifecycle%20Management%20Server%201.3
Affected ranges
Type: ECOSYSTEM
Events:
