Division by zero in FastNetMon - CVE-2024-56073
Published: December 30, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a divide by zero error when handling zero-length templates for Netflow v9 within the process_netflow_v9_options_template() function in src/netflow_plugin/netflow_v9_collector.cpp. A remote attacker can perform a denial of service (DoS) attack.
Affected software
Debian Linux
fastnetmon (Debian package)
How to mitigate CVE-2024-56073
fastnetmon (Debian package) - update to 1.2.4-2+deb12u1