Denial of Service in Packetbeat
High severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Feb 14, 2023
Package
Affected versions
< 5.6.4
>= 6.0.0-alpha1, < 6.0.0
Patched versions
5.6.4
6.0.0
Description
Reviewed
May 19, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Feb 14, 2023
Packetbeat versions prior to 5.6.4 and 6.0.0 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.
References