CVE-2023-38403

Name
CVE-2023-38403
Description
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9
MISC https://bugs.debian.org/1040830
MISC https://github.com/esnet/iperf/issues/1542
MISC https://downloads.es.net/pub/iperf/esnet-secadv-2023-0001.txt.asc
MISC https://cwe.mitre.org/data/definitions/130.html
MLIST https://lists.debian.org/debian-lts-announce/2023/07/msg00025.html
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M25Z5FHTO3XWMGP37JHJ7IIIHSGCLKEV/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BV6EBWWF4PEQKROEVXGYSTIT2MGBTLU7/
CONFIRM https://security.netapp.com/advisory/ntap-20230818-0016/
CONFIRM https://support.apple.com/kb/HT213985
CONFIRM https://support.apple.com/kb/HT213984
FULLDISC http://seclists.org/fulldisclosure/2023/Oct/26
FULLDISC http://seclists.org/fulldisclosure/2023/Oct/24
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M25Z5FHTO3XWMGP37JHJ7IIIHSGCLKEV/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BV6EBWWF4PEQKROEVXGYSTIT2MGBTLU7/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:es:iperf3:*:*:*:*:*:*:*:* iperf3 >= None < 3.14

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
iperf3 3.17-main 3.12-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
iperf3 3.16-main 3.11-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
iperf3 3.15-main 3.10.1-r1 Natanael Copa <ncopa@alpinelinux.org> fixed