Infinite loop in OpenWSMAN - CVE-2019-3833
Published: April 18, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the process_connection() function when processing HTTP requests. A remote attacker can send a specially crafted HTTP request to the affected server and consume all available system resources and cause denial of service conditions.
Affected software
openwsman (Red Hat package)
openwsman (Alpine package)
openwsman
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Opensuse
Fedora
How to mitigate CVE-2019-3833
openwsman - addressed in versions 2.6.5-4.fc28, 2.6.5-9.fc29, 2.6.8-5.fc30
External References
- http://bugzilla.suse.com/show_bug.cgi?id=1122623
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00065.html
- http://www.securityfocus.com/bid/107367
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3833
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2V5HJ355RSKMFQ7GRJAHRZNDVXASF7TA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B2HEZ7D7GF3HDF36JLGYXIK5URR66DS4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CXQP7UDPRZIZ4LM7FEJCTC2EDUYVOR2J/
Related Security Bulletins
- OpenSUSE Linux update for openwsman
- OpenSUSE Linux update for openwsman
- Infinite loop in openwsman (Alpine package)
- Red Hat Enterprise Linux 7 update for openwsman
- Red Hat Enterprise Linux 8 update for openwsman
- Fedora 30 update for openwsman
- Fedora 29 update for openwsman
- Fedora 28 update for openwsman