REDHAT-BUG-1439674: Medium severity collectd vulnerability
Incorrect interaction of the parsepacket() and parsepartsignsha256() functions in network.c in collectd allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.
Upstream bug:
https://github.com/collectd/collectd/issues/2174
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1439674?
The severity of REDHAT-BUG-1439674 is categorized as a denial of service vulnerability.
How do I fix REDHAT-BUG-1439674?
To fix REDHAT-BUG-1439674, configure collectd with a valid 'AuthFile' and avoid using 'SecurityLevel None'.
What systems are affected by REDHAT-BUG-1439674?
REDHAT-BUG-1439674 affects collectd instances configured with 'SecurityLevel None' and empty 'AuthFile' options.
Can REDHAT-BUG-1439674 be exploited remotely?
Yes, REDHAT-BUG-1439674 can be exploited remotely via crafted UDP packets.
What is the impact of REDHAT-BUG-1439674?
The impact of REDHAT-BUG-1439674 is an infinite loop that causes a denial of service in collectd.