{"id":"CVE-2023-38403","details":"iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.","modified":"2026-08-12T03:30:39.794028470Z","published":"2023-07-17T00:00:00Z","related":["ALSA-2023:4570","ALSA-2023:4571","SUSE-SU-2023:2987-1","SUSE-SU-2023:3887-1","openSUSE-SU-2024:13060-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38403.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://bugs.debian.org/1040830"},{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/130.html"},{"type":"WEB","url":"https://downloads.es.net/pub/iperf/esnet-secadv-2023-0001.txt.asc"},{"type":"WEB","url":"https://support.apple.com/kb/HT213984"},{"type":"WEB","url":"https://support.apple.com/kb/HT213985"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38403.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BV6EBWWF4PEQKROEVXGYSTIT2MGBTLU7/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M25Z5FHTO3XWMGP37JHJ7IIIHSGCLKEV/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38403"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230818-0016/"},{"type":"REPORT","url":"https://github.com/esnet/iperf/issues/1542"},{"type":"FIX","url":"https://github.com/esnet/iperf/commit/0ef151550d96cc4460f98832df84b4a1e87c65e9"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2023/Oct/24"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2023/Oct/26"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/07/msg00025.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/esnet/iperf","events":[{"introduced":"6f6716aed146d5e2293f94b2ac44f6189f2ccd27"},{"fixed":"a0be85934144bc04712a6695b14ea6e45c379e1d"}],"database_specific":{"extracted_events":[{"introduced":"iperf3"},{"fixed":"3.14"}],"source":"DESCRIPTION"}}],"versions":["3.13","3.12","3.11","3.10.1","3.10","3.9","3.8.1","3.8","3.7","3.6","3.5","3.4","3.3","3.2","3.2rc1","3.1","3.1b3","3.1b2","3.1b1","3.0.4","3.0.1","3.0-BETA5","3.0-BETA4","3.0-BETA3","3.0-BETA2","3.0-BETA1","iperf3","3.0-ALPHA1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-38403.json"}}],"schema_version":"1.9.0"}