CVE-2010-4336: Medium severity collectd vulnerability
Published Dec 17, 2010
·Updated
The currdcreatefile function (src/utilsrrdcreate.c) in collectd 4.x before 4.9.4 and before 4.10.2 allow remote attackers to cause a denial of service (assertion failure) via a packet with a timestamp whose value is 10 or less, as demonstrated by creating RRD files using the (1) RRDtool and (2) RRDCacheD plugins.
Affected Software
65 affected components
collectd collectd=4.9.0
collectd collectd=4.1.6
collectd collectd=4.6.3
collectd collectd=4.6.2
collectd collectd=4.2.6
collectd collectd=4.3.4
collectd collectd=4.0.6
collectd collectd=4.2.5
collectd collectd=4.2.7
collectd collectd=4.2.2
collectd collectd=4.6.0
collectd collectd=4.9.2
collectd collectd=4.8.3
collectd collectd=4.0.5
collectd collectd=4.3.1
collectd collectd=4.0.7
collectd collectd=4.3.3
collectd collectd=4.8.5
collectd collectd=4.8.4
collectd collectd=4.6.5
collectd collectd=4.1.0
collectd collectd=4.1.5
collectd collectd=4.8.0
collectd collectd=4.7.2
collectd collectd=4.1.4
collectd collectd=4.1.3
collectd collectd=4.7.5
collectd collectd=4.8.1
collectd collectd=4.0.4
collectd collectd=4.10.1
collectd collectd=4.9.1
collectd collectd=4.2.0
collectd collectd=4.4.2
collectd collectd=4.5.4
collectd collectd=4.0.1
collectd collectd=4.2.4
collectd collectd=4.4.3
collectd collectd=4.7.4
collectd collectd=4.0.2
collectd collectd=4.10
collectd collectd=4.1.1
collectd collectd=4.4.4
collectd collectd=4.5.0
collectd collectd=4.9.3
collectd collectd=4.0.0
collectd collectd=4.8.2
collectd collectd=4.7.0
collectd collectd=4.1.2
collectd collectd=4.5.1
collectd collectd=4.0.9
collectd collectd=4.4.5
collectd collectd=4.6.4
collectd collectd=4.2.3
collectd collectd=4.7.3
collectd collectd=4.3.0
collectd collectd=4.5.2
collectd collectd=4.2.1
collectd collectd=4.4.1
collectd collectd=4.7.1
collectd collectd=4.0.3
collectd collectd=4.4.0
collectd collectd=4.0.8
collectd collectd=4.5.3
collectd collectd=4.6.1
collectd collectd=4.3.2
Event History
Dec 17, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4336?
CVE-2010-4336 is classified as a denial of service vulnerability.
2
How do I fix CVE-2010-4336?
To fix CVE-2010-4336, upgrade to collectd version 4.9.4 or 4.10.2 or later.
3
What versions of collectd are affected by CVE-2010-4336?
CVE-2010-4336 affects collectd versions 4.x before 4.9.4 and before 4.10.2.
4
What type of attack does CVE-2010-4336 enable?
CVE-2010-4336 enables remote attackers to cause a denial of service through specific packet manipulation.
5
What is the function involved in CVE-2010-4336?
The vulnerability is located in the cu_rrd_create_file function within collectd.