USN-4788-1: iperf3 vulnerability
15 March 2021
iperf3 could be made to crash or run programs as an administrator.
Releases
Packages
- iperf3 - Internet Protocol bandwidth measuring tool
Details
It was discovered that iperf mishandled certain UTF-8 and UTF-16 strings.
A remote attacker could use this vulnerability to cause a denial of service
or possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
iperf3
-
3.0.11-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.