iperf3-3.5-10.el8_10

エラータID: AXSA:2024-8525:01

Release date: 
Friday, July 5, 2024 - 14:56
Subject: 
iperf3-3.5-10.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.

Security Fix(es):

* iperf3: possible denial of service (CVE-2023-7250)
* iperf3: vulnerable to marvin attack if the authentication option is used (CVE-2024-26306)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-7250
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.
CVE-2024-26306
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. iperf3-3.5-10.el8_10.src.rpm
    MD5: 2a0e232a98b0b128830783f57b2a7cf8
    SHA-256: 7c61553d4715e61f0a063e0367e0854ed5e6be91029507d1b63f27a9dd847629
    Size: 604.68 kB

Asianux Server 8 for x86_64
  1. iperf3-3.5-10.el8_10.i686.rpm
    MD5: fb116ec1f90ca3a9aa1617f1c95d2a17
    SHA-256: cce973c3bdcc8ea7a0e9099f178384bc0f91247b37d120cbbe3018d3c75a3f56
    Size: 107.87 kB
  2. iperf3-3.5-10.el8_10.x86_64.rpm
    MD5: 82070c6216068d879ce284add9d214bb
    SHA-256: da706cf2628b4be4c64b3540b7480e269974d79977795ee4079cb1928dde5ee5
    Size: 100.94 kB