CVE-2017-7401: High severity collectd collectd vulnerability
Incorrect interaction of the parsepacket() and parsepartsignsha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.
Other sources
Incorrect interaction of the parsepacket() and parsepartsignsha256() functions in network.c in collectd allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.
Upstream bug:
https://github.com/collectd/collectd/issues/2174
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
collectdto a version that resolves this vulnerability.Fixed in 5.7.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7401?
CVE-2017-7401 is classified as a denial of service vulnerability due to an infinite loop in collectd.
How do I fix CVE-2017-7401?
To fix CVE-2017-7401, upgrade collectd to version 5.7.2 or later.
What software is affected by CVE-2017-7401?
CVE-2017-7401 affects collectd versions 5.7.1 and earlier.
Can CVE-2017-7401 be exploited remotely?
Yes, CVE-2017-7401 can be exploited remotely by attackers if collectd is configured with 'SecurityLevel None' and has empty 'AuthFile' options.
What impact does CVE-2017-7401 have on systems?
CVE-2017-7401 can cause a denial of service, leading to unresponsive collectd instances.