Infinite loop in OpenWSMAN - CVE-2019-3833

 

Infinite loop in OpenWSMAN - CVE-2019-3833

Published: April 18, 2019


Vulnerability identifier: #VU18314
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3833
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the process_connection() function when processing HTTP requests. A remote attacker can send a specially crafted HTTP request to the affected server and consume all available system resources and cause denial of service conditions.


Affected software

OpenWSMAN
openwsman (Red Hat package)
openwsman (Alpine package)
openwsman
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Opensuse
Fedora

How to mitigate CVE-2019-3833

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

openwsman (Red Hat package) - addressed in versions 2.6.3-7.git4391e5c.el7, 2.6.5-7.el8
openwsman - addressed in versions 2.6.5-4.fc28, 2.6.5-9.fc29, 2.6.8-5.fc30

External References

Related Security Bulletins