CVE-2013-7441
nbd - security update
EPSS 3.7%
描述
The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.
如何修補 CVE-2013-7441
要修補 CVE-2013-7441,請將受影響套件升級到下列已修補版本。
- Debian/nbd—升級至 1:3.4-1 或更新版本
- Debian/nbd—升級至 1:3.2-4~deb7u5 或更新版本
CVE-2013-7441 正在被利用嗎?
低 — EPSS 為 3.7%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1:3.4-1
- from 0, < 1:3.2-4~deb7u5