iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"31138989934835967853644463147944633206",
"300129804459515635418185354063148005800",
"211185849642239104369431138118764752128",
"120289198626001640135016292307456648609",
"103946030697011972946752526404262707110",
"74265392440462843323174286899530357374",
"317375933644696769020399486204161531528",
"286784827784628466018746909541478291355",
"44075911177452260091104907090409103549",
"252582931826044103934091042691051999819",
"260211622875497584537767243227104153086",
"334182649030972681018623345589886499362"
]
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-38403-2f181cff",
"target": {
"file": "src/iperf_api.c"
},
"source": "https://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9",
"signature_type": "Line"
},
{
"digest": {
"function_hash": "4224136192845182230612297700002105072",
"length": 534.0
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-38403-b779251d",
"target": {
"file": "src/iperf_api.c",
"function": "JSON_read"
},
"source": "https://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9",
"signature_type": "Function"
}
]