Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.
References
| Link | Resource |
|---|---|
| https://www.elastic.co/community/security | Vendor Advisory |
Configurations
Information
Published : 2017-06-16 14:29
Updated : 2019-10-09 16:16
NVD link : CVE-2016-10363
Mitre link : CVE-2016-10363
JSON object : View
CWE
CWE-404
Improper Resource Shutdown or Release
Products Affected
elastic
- logstash


