One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 8313022
Date de publication 2023-02-23 22:15:11 (vue: 2023-02-24 00:08:17)
Titre CVE-2023-25824
Texte Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop retrying the read operation, consuming CPU resources. This could be exploited for denial of service attacks. If trace level logging was enabled, it would also produce an excessive amount of log output during the loop, consuming disk space. The problem has been fixed in commit d7eec4e598158ab6a98bf505354e84352f9715ec, please update to version 0.12.1. There are no workarounds, users who cannot update should apply the errno fix detailed in the security advisory.
Envoyé Oui
Condensat 2023 25824 advisory also amount apache apply are attacks based been blocking cannot commit connections consuming could cpu cve d7eec4e598158ab6a98bf505354e84352f9715ec denial detailed did disk during enabled endless entered errno excessive exploited fail fix fixed from gnutls has hit httpd including instead level log logging loop mod module not operation operations output please problem produce properly read resources retrying security service should space timeouts tls trace transport update users version versions when who workarounds would
Tags
Stories
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: