Vulnerabilities > CVE-2015-0847 - Code vulnerability in multiple products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Ubuntu Local Security Checks NASL id UBUNTU_USN-2676-1.NASL description It was discovered that NBD incorrectly handled IP address matching. A remote attacker could use this issue with an IP address that has a partial match and bypass access restrictions. This issue only affected Ubuntu 12.04 LTS. (CVE-2013-6410) Tuomas Rasanen discovered that NBD incorrectly handled wrong export names and closed connections during negotiation. A remote attacker could use this issue to cause NBD to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS. (CVE-2013-7441) Tuomas Rasanen discovered that NBD incorrectly handled signals. A remote attacker could use this issue to cause NBD to crash, resulting in a denial of service. (CVE-2015-0847). Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 84958 published 2015-07-23 reporter Ubuntu Security Notice (C) 2015-2019 Canonical, Inc. / NASL script (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/84958 title Ubuntu 12.04 LTS / 14.04 LTS / 14.10 / 15.04 : nbd vulnerabilities (USN-2676-1) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-3271.NASL description Tuomas Rasanen discovered that unsafe signal handling in nbd-server, the server for the Network Block Device protocol, could allow remote attackers to cause a deadlock in the server process and thus a denial of service. Tuomas Rasanen also discovered that the modern-style negotiation was carried out in the main server process before forking the actual client handler. This could allow a remote attacker to cause a denial of service (crash) by querying a non-existent export. This issue only affected the oldstable distribution (wheezy). last seen 2020-06-01 modified 2020-06-02 plugin id 83788 published 2015-05-26 reporter This script is Copyright (C) 2015-2018 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/83788 title Debian DSA-3271-1 : nbd - security update NASL family SuSE Local Security Checks NASL id OPENSUSE-2015-393.NASL description - Fix CVE-2013-7441 (boo#931987) - CVE-2013-7441.patch - Fix CVE-2015-0847 (boo#930173) - nbd_signaling_CVE-2015-0847.patch last seen 2020-06-05 modified 2015-06-04 plugin id 83981 published 2015-06-04 reporter This script is Copyright (C) 2015-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/83981 title openSUSE Security Update : nbd (openSUSE-2015-393) NASL family Fedora Local Security Checks NASL id FEDORA_2015-12703.NASL description - Fix unsafe signal handlers to avoid DoS attack [CVE-2015-0847]. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-05 modified 2015-08-14 plugin id 85391 published 2015-08-14 reporter This script is Copyright (C) 2015-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/85391 title Fedora 21 : nbd-3.11-1.fc21 (2015-12703) NASL family Debian Local Security Checks NASL id DEBIAN_DLA-223.NASL description A vulnerability has been discovered in nbd-server, the server for the Linux Network Block Device. CVE-2015-0847 Tuomas Räsänen discovered that unsafe signal handling is present in nbd-server. This vulnerability could be exploited by a remote client to cause a denial of service. For the oldoldstable distribution (squeeze), these problems have been fixed in version 1:2.9.16-8+squeeze2. For the oldstable, stable, and testing distributions, these problems will be fixed soon. We recommend that you upgrade your nbd-server packages. -- Wouter Verhelst NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-03-17 modified 2015-05-18 plugin id 83500 published 2015-05-18 reporter This script is Copyright (C) 2015-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/83500 title Debian DLA-223-1 : nbd security update NASL family Fedora Local Security Checks NASL id FEDORA_2015-12719.NASL description - Fix unsafe signal handlers to avoid DoS attack [CVE-2015-0847]. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-05 modified 2015-08-14 plugin id 85392 published 2015-08-14 reporter This script is Copyright (C) 2015-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/85392 title Fedora 22 : nbd-3.11-1.fc22 (2015-12719)
References
- http://lists.opensuse.org/opensuse-updates/2015-06/msg00003.html
- http://sourceforge.net/p/nbd/mailman/message/34091218/
- http://sourceforge.net/projects/nbd/files/nbd/3.11/
- http://www.debian.org/security/2015/dsa-3271
- http://www.openwall.com/lists/oss-security/2015/05/07/9
- http://www.ubuntu.com/usn/USN-2676-1