collectd is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues to cause a denial-of-service condition.
collectd 5.7.1 is vulnerable; other versions may also be affected.
Information
Exploit
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References:
- Endless loop in parse_packet() while statement (CPU drain/DoS) #2174 (collectd)
- collectd Homepage (collectd)