Bug 6917 - [Anolis OS 23] Bugfix for CVE-2023-38403
Summary: [Anolis OS 23] Bugfix for CVE-2023-38403
Status: RESOLVED FIXED
Alias: None
Product: Anolis OS 23
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: unspecified
Hardware: All Linux
: P3-Medium S3-normal
Target Milestone: ---
Assignee: happy_orange
QA Contact: bolong_tbl
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-10-18 16:47 UTC by 小龙
Modified: 2023-10-18 16:47 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-10-18 16:47:05 UTC
Description:
3.14之前的iperf3允许对等方通过精心设计的长度字段导致整数溢出和堆损坏。

Broken commit info:

Bugfix commit info:
https://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9
https://github.com/esnet/iperf/pull/1543
Comment 1 小龙 admin 2023-10-18 16:47:23 UTC
PR: 
https://gitee.com/src-anolis-os/iperf3/pulls/4