USN-4793-1: collectd vulnerabilities
15 March 2021
Several security issues were fixed in collectd.
Releases
Packages
- collectd - statistics collection and monitoring daemon
Details
It was discovered that collectd mishandled certain malformed packets. A
remote attacker could use this vulnerability to cause collectd to crash or
possibly execute arbitrary code. (CVE-2016-6254)
It was discovered that collectd failed to handle certain input. An attacker
could use this vulnerability to cause collectd to crash. (CVE-2017-16820)
It was discovered that collectd mishandles certain malformed network
packets. A remote attacker could use this vulnerability to cause a Denial of
Service or consume system resources. (CVE-2017-7401)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libcollectdclient1
-
5.5.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
collectd
-
5.5.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
collectd-core
-
5.5.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
libcollectdclient1
-
5.4.0-3ubuntu2.2+esm1
Available with Ubuntu Pro
-
collectd
-
5.4.0-3ubuntu2.2+esm1
Available with Ubuntu Pro
-
collectd-core
-
5.4.0-3ubuntu2.2+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.