Red Hat Security Advisory 2017-1787-01

Discussion in 'News Aggregator' started by Packet Storm, 22 Jul 2017.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2017-1787-01 - collectd is a small C-language daemon, which reads various system metrics periodically and updates RRD files. Because the daemon does not start up each time it updates files, it has a low system footprint. The following packages have been upgraded to a later upstream version: collectd. Security Fix: collectd contains an infinite loop due to how the parse_packet() and parse_part_sign_sha256() functions interact. If an instance of collectd is configured with "SecurityLevel None" and empty "AuthFile" options, an attacker can send crafted UDP packets that trigger the infinite loop, causing a denial of service.

    Continue reading...
     

Share This Page

Loading...