Home

Description

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

PUBLISHED Reserved 2025-07-21 | Published 2025-08-03 | Updated 2025-11-03 | Assigner mitre




MEDIUM: 6.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Problem types

CWE-193 Off-by-one Error

Product status

Default status
unaffected

Any version before 3.19.1
affected

References

lists.debian.org/debian-lts-announce/2025/08/msg00020.html

github.com/...ommit/4e5313bab0b9b3fe03513ab54f722c8a3e4b7bdf

github.com/esnet/iperf/releases/tag/3.19.1

cve.org (CVE-2025-54349)

nvd.nist.gov (CVE-2025-54349)

Download JSON