Buffer overflow in fastd - CVE-2020-27638
Published: October 22, 2020 / Updated: November 1, 2020
Vulnerability identifier: #VU48061
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27638
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
Affected software
fastd
Fedora
Ubuntu
fastd (Ubuntu package)
fastd (Alpine package)
fastd
Fedora
Ubuntu
fastd (Ubuntu package)
fastd (Alpine package)
fastd
How to mitigate CVE-2020-27638
Install update from vendor's website.
fastd (Ubuntu package) - addressed in versions 17-4ubuntu0.1, 18-3ubuntu0.18.04.1, 19-3ubuntu0.1
fastd (Alpine package) - update to 21-r0
fastd - addressed in versions 21-1.el8, 21-1.fc31, 21-1.fc32, 21-1.fc33, 21-2.el7
fastd (Alpine package) - update to 21-r0
fastd - addressed in versions 21-1.el8, 21-1.fc31, 21-1.fc32, 21-1.fc33, 21-2.el7