High severity7.5NVD Advisory· Published Dec 8, 2017· Updated Jun 17, 2026
CVE-2017-11480
CVE-2017-11480
Description
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/elastic/beatsGo | < 5.6.4 | 5.6.4 |
github.com/elastic/beatsGo | >= 6.0.0-alpha1, < 6.0.0 | 6.0.0 |
Affected products
3cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*range: <5.6.4
- (no CPE)range: before 5.6.4
Patches
Vulnerability mechanics
References
8- discuss.elastic.co/t/beats-5-6-4-security-update/106739nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-9q3g-m353-cp4pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-11480ghsaADVISORY
- github.com/elastic/beats/commit/aeca65779d573976981587ca1d1461399e1b59ddghsaWEB
- github.com/elastic/beats/pull/5457ghsaWEB
- github.com/elastic/beats/pull/5479ghsaWEB
- github.com/elastic/beats/pull/5480ghsaWEB
- pkg.go.dev/vuln/GO-2022-0643ghsaWEB
News mentions
0No linked articles in our index yet.