CVE-2017-11480

Severity CVSS v4.0:
Pending analysis
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
08/12/2017
Last modified:
20/04/2025

Description

Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:* 5.6.4 (excluding)