UBUNTU-CVE-2021-3716
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3716
Summary:
Details: A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.
References: https://ubuntu.com/security/CVE-2021-3716, https://access.redhat.com/security/cve/CVE-2021-3716, https://listman.redhat.com/archives/libguestfs/2021-August/msg00077.html, https://www.cve.org/CVERecord?id=CVE-2021-3716
Affected packages
Package
Name: nbdkit
Purl: pkg:deb/ubuntu/nbdkit?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
