CVE-2023-4785
Summary
| CVE | CVE-2023-4785 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-13 17:15:00 UTC |
| Updated | 2023-09-19 16:02:00 UTC |
| Description | Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [backport][iomgr][EventEngine] Improve server handling of file descriptor exhaustion by drfloob · Pull Request #33670 · grpc/grpc · GitHub | MISC | github.com | |
| [backport][iomgr][EventEngine] Improve server handling of file descriptor exhaustion by drfloob · Pull Request #33669 · grpc/grpc · GitHub | MISC | github.com | |
| [iomgr][EventEngine] Improve server handling of file descriptor exhaustion by drfloob · Pull Request #33656 · grpc/grpc · GitHub | MISC | github.com | |
| [backport][iomgr][EventEngine] Improve server handling of file descriptor exhaustion by drfloob · Pull Request #33672 · grpc/grpc · GitHub | MISC | github.com | |
| [backport][iomgr][EventEngine] Improve server handling of file descriptor exhaustion by drfloob · Pull Request #33667 · grpc/grpc · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 242923 Red Hat Update for Satellite 6.14.2 (RHSA-2024:0797)
- 673647 EulerOS Security Update for grpc (EulerOS-SA-2023-3243)
- 673764 EulerOS Security Update for grpc (EulerOS-SA-2023-3179)
- 673987 EulerOS Security Update for grpc (EulerOS-SA-2023-3300)
- 674009 EulerOS Security Update for grpc (EulerOS-SA-2023-3332)
- 674014 EulerOS Security Update for grpc (EulerOS-SA-2023-3271)
- 674065 EulerOS Security Update for grpc (EulerOS-SA-2023-3214)
- 755815 SUSE Enterprise Linux Security Update for abseil-cpp, grpc, opencensus-proto, protobuf, python-abseil, python-grpcio, re2 (SUSE-SU-2024:0573-1)
- 997223 Python (Pip) Security Update for grpc (GHSA-p25m-jpj4-qcrr)
- 997224 Rubygems (Rubygems) Security Update for grpc (GHSA-p25m-jpj4-qcrr)