Resource management error in Mesos - CVE-2018-11793

 

Resource management error in Mesos - CVE-2018-11793

Published: March 6, 2019


Vulnerability identifier: #VU17911
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11793
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect processing of nested data within a JSON array. A remote unauthenticated attacker can supply a specially crafted JSON array,  overflow the stack due to unbounded recursion and perform denial of service (DoS) attack,


Affected software

Mesos
Netcool Operations Insight
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2018-11793

Install updates from vendor's website.

Mesos - update to 1.7.1
Netcool Operations Insight - update to 1.6.8
IBM Cloud Pak for Watson AIOps - update to 3.7.1

External References

Related Security Bulletins