CVE-2017-11480

HIGH7.5EPSS 0.54%

Denial of Service in Packetbeat

Published: 2/15/2022Modified: 11/8/2023
Also known as:GHSA-9q3g-m353-cp4pGO-2022-0643

Description

Packetbeat versions prior to 5.6.4 and 6.0.0 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (8)