CVE-2013-7441: High severity Wouter Verhelst Nbd vulnerability
Published Mar 30, 2015
·Updated
The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.
Affected Software
17 affected componentsFixes available
debian/nbd
1:3.19-3+deb10u11:3.21-1+deb11u11:3.24-1.11:3.25-1
Wouter Verhelst Nbd=2.9.3
Wouter Verhelst Nbd=2.9.4
Wouter Verhelst Nbd=2.9.5
Wouter Verhelst Nbd=2.9.6
Wouter Verhelst Nbd=2.9.7
Wouter Verhelst Nbd=2.9.8
Wouter Verhelst Nbd=2.9.9
Wouter Verhelst Nbd=2.9.22
Wouter Verhelst Nbd=2.9.23
Wouter Verhelst Nbd=2.9.24
Wouter Verhelst Nbd=2.9.25
Wouter Verhelst Nbd=3.0
Wouter Verhelst Nbd=3.1
Wouter Verhelst Nbd=3.1.1
Wouter Verhelst Nbd=3.2
Wouter Verhelst Nbd=3.3
Event History
Mar 30, 2015
Data Sourced
08:45 PM
SeverityAffected Software
May 29, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-7441?
CVE-2013-7441 has a severity that can lead to denial of service by terminating the root process.
2
How do I fix CVE-2013-7441?
To fix CVE-2013-7441, update NBD server to version 3.4 or later.
3
What versions of NBD are affected by CVE-2013-7441?
CVE-2013-7441 affects NBD server versions 2.9.22 through 3.3.
4
Can CVE-2013-7441 allow remote attacks?
Yes, CVE-2013-7441 enables remote attackers to exploit vulnerabilities during the negotiation process.
5
What methods can attackers use to exploit CVE-2013-7441?
Attackers can exploit CVE-2013-7441 by closing the connection during negotiation or using a non-existent export name.