5
CVSSv2

CVE-2010-4336

Published: 17/12/2010 Updated: 21/02/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The cu_rrd_create_file function (src/utils_rrdcreate.c) in collectd 4.x prior to 4.9.4 and prior to 4.10.2 allow remote malicious users to cause a denial of service (assertion failure) via a packet with a timestamp whose value is 10 or less, as demonstrated by creating RRD files using the (1) RRDtool and (2) RRDCacheD plugins.

Vulnerable Product Search on Vulmon Subscribe to Product

collectd collectd 4.0.6

collectd collectd 4.0.7

collectd collectd 4.8.5

collectd collectd 4.8.4

collectd collectd 4.7.3

collectd collectd 4.7.2

collectd collectd 4.6.1

collectd collectd 4.6.0

collectd collectd 4.4.3

collectd collectd 4.4.2

collectd collectd 4.3.0

collectd collectd 4.2.7

collectd collectd 4.2.0

collectd collectd 4.1.6

collectd collectd 4.0.4

collectd collectd 4.0.5

collectd collectd 4.9.2

collectd collectd 4.9.1

collectd collectd 4.9.0

collectd collectd 4.7.5

collectd collectd 4.7.4

collectd collectd 4.6.3

collectd collectd 4.6.2

collectd collectd 4.4.5

collectd collectd 4.4.4

collectd collectd 4.3.2

collectd collectd 4.3.1

collectd collectd 4.2.2

collectd collectd 4.2.1

collectd collectd 4.1.0

collectd collectd 4.0.9

collectd collectd 4.0.2

collectd collectd 4.0.3

collectd collectd 4.10

collectd collectd 4.9.3

collectd collectd 4.8.1

collectd collectd 4.8.0

collectd collectd 4.6.5

collectd collectd 4.6.4

collectd collectd 4.5.2

collectd collectd 4.5.1

collectd collectd 4.5.0

collectd collectd 4.3.4

collectd collectd 4.3.3

collectd collectd 4.2.4

collectd collectd 4.2.3

collectd collectd 4.1.2

collectd collectd 4.1.1

collectd collectd 4.0.0

collectd collectd 4.0.1

collectd collectd 4.0.8

collectd collectd 4.10.1

collectd collectd 4.8.3

collectd collectd 4.8.2

collectd collectd 4.7.1

collectd collectd 4.7.0

collectd collectd 4.5.4

collectd collectd 4.5.3

collectd collectd 4.4.1

collectd collectd 4.4.0

collectd collectd 4.2.6

collectd collectd 4.2.5

collectd collectd 4.1.5

collectd collectd 4.1.4

collectd collectd 4.1.3

Vendor Advisories

Debian Bug report logs - #605092 Denial of Service vulnerability in the RRDtool and RRDCacheD plugins Package: collectd; Maintainer for collectd is Sebastian Harl <tokkee@debianorg>; Source for collectd is src:collectd (PTS, buildd, popcon) Reported by: Florian Forster <octo@collectdorg> Date: Sat, 27 Nov 2010 12: ...
It was discovered that collectd, a statistics collection and monitoring daemon, is prone to a denial of service attack via a crafted network packet For the stable distribution (lenny), this problem has been fixed in version 442-3+lenny1 For the testing distribution (squeeze), this problem has been fixed in version 4101-1+squeeze2 For the uns ...