CVE-2021-3716

CVE-2021-3716

A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.

Source: CVE-2021-3716

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다