USN-2676-1
Dashboard / Vulnerabilities / USN-2676-1
USN-2676-1
Summary: nbd vulnerabilities
Details: It was discovered that NBD incorrectly handled IP address matching. A remote attacker could use this issue with an IP address that has a partial match and bypass access restrictions. This issue only affected Ubuntu 12.04 LTS. (CVE-2013-6410) Tuomas Räsänen discovered that NBD incorrectly handled wrong export names and closed connections during negotiation. A remote attacker could use this issue to cause NBD to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS. (CVE-2013-7441) Tuomas Räsänen discovered that NBD incorrectly handled signals. A remote attacker could use this issue to cause NBD to crash, resulting in a denial of service. (CVE-2015-0847)
References: https://ubuntu.com/security/notices/USN-2676-1, https://ubuntu.com/security/CVE-2013-6410, https://ubuntu.com/security/CVE-2013-7441, https://ubuntu.com/security/CVE-2015-0847
Affected packages
Package
Name: nbd
Purl: pkg:deb/ubuntu/nbd@1:3.7-1ubuntu0.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
