Resource exhaustion in postsrsd - CVE-2020-35573
Published: December 23, 2020
Vulnerability identifier: #VU49128
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35573
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address.
Affected software
postsrsd
Gentoo Linux
Ubuntu
postsrsd (Alpine package)
postsrsd (Ubuntu package)
Gentoo Linux
Ubuntu
postsrsd (Alpine package)
postsrsd (Ubuntu package)
How to mitigate CVE-2020-35573
Install update from vendor's website.
postsrsd - update to 1.1
postsrsd (Alpine package) - update to 1.6-r4
postsrsd (Ubuntu package) - update to 1.4-1ubuntu0.1
postsrsd (Alpine package) - update to 1.6-r4
postsrsd (Ubuntu package) - update to 1.4-1ubuntu0.1