USN-7966-2
Dashboard / Vulnerabilities / USN-7966-2
USN-7966-2
Summary: telegraf vulnerabilities
Details: USN-7966-1 fixed vulnerabilities in Snowflake. This update provides the corresponding updates for Telegraf. Original advisory details: It was discovered that Pion DTLS, vendored in Telegraf, did not impose a limit on the amount of data that was buffered during the handshake. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29189) It was discovered that Pion DTLS, vendored in Telegraf, did not prevent the fragmentBuffer from processing zero length fragments. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29190) It was discovered that Pion DTLS, vendored in Telegraf, did not require CertificateVerify when Client Cert was sent. An attacker could possibly use the issue to cause a denial of service. (CVE-2022-29222)
References: https://ubuntu.com/security/notices/USN-7966-2, https://ubuntu.com/security/CVE-2022-29189, https://ubuntu.com/security/CVE-2022-29190, https://ubuntu.com/security/CVE-2022-29222
Affected packages
Package
Name: telegraf
Purl: pkg:deb/ubuntu/[email protected]+ds1-0ubuntu2+esm2?arch=source&distro=esm-apps/jammy
Affected ranges
Type: ECOSYSTEM
Events:
