EulerOS 2.0 SP8 : grpc (EulerOS-SA-2024-2470)
Discription

According to the versions of the grpc package installed, the EulerOS installation on the remote host is affected by the following vulnerabilities : Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.(CVE-2023-4785) Tenable has extracted the preceding description block directly from the EulerOS grpc security advisory. Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version…Read More

Back to Main

Subscribe for the latest news: