Intrusion Prevention

ESnet.iPerf3.JSON.Parser.UTF.Code.Memory.Corruption

Description

This indicates an attack attempt to exploit a Memory Corruption vulnerability in ESnet iPerf3.
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted request. A remote attacker may be able to exploit this to execute arbitrary code within the context of the application, via a crafted request.

Affected Products

ESnet iPerf3 version 3.0.11 or prior
ESnet iPerf3 version 3.1.2 or prior

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most upgrade or patch to version 3.1.3 or 2.0.12 or above from the vendor.
http://software.es.net/iperf/news.html#security-issue-iperf-3-1-3-iperf-3-0-12-released

CVE References

CVE-2016-4303