Out-of-bounds write in bzip2 - CVE-2019-12900

 

Out-of-bounds write in bzip2 - CVE-2019-12900

Published: July 15, 2019


Vulnerability identifier: #VU19178
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12900
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the BZ2_decompress() function in decompress.c. A remote attacker can create a specially crafted archive, trick the victim into opening it using the affected library, trigger out-of-bounds write and execute arbitrary code on the target system.

Affected software

bzip2
Submariner
IBM Concert Software
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
Service Interconnect
Multicluster GlobalHub
Red Hat Integration Camel-K
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Red Hat OpenStack
ClamAV
bzip2 (Alpine package)
clamav
bzip2
bzip2-devel
bzip2-libs
bzip2-static
bzip2 (Red Hat package)
watsonx.data
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
IBM QRadar Incident Forensics
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
FreeBSD
Slackware Linux
Opensuse
IBM API Connect
Oracle Database Server
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Dell EMC AppSync
RSA Authentication Manager
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
IBM Qradar SIEM
IBM License Metric Tool
Juniper Secure Analytics (JSA)
Red Hat Ceph Storage

How to mitigate CVE-2019-12900

Install update from vendor's website.

Submariner - addressed in versions 0.16.8, 0.18.5
ClamAV - update to 0.101.4
IBM Concert Software - update to 1.1.0
bzip2 (Alpine package) - update to 1.0.6-r7
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.1.2
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM API Connect - update to 10.0.8.2 ifix2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
clamav - addressed in versions 0.101.4-1.el7, 0.101.4-1.el8, 0.101.4-1.fc29, 0.101.4-1.fc30
Service Interconnect - addressed in versions 1, 1.4
Red Hat OpenShift Serverless - update to 1
bzip2 - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-devel - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-libs - addressed in versions 1.0.6-27, 1.0.6-28
bzip2-static - addressed in versions 1.0.6-27, 1.0.6-28
bzip2 (Red Hat package) - addressed in versions 1.0.6-27.el8_10, 1.0.6-28.el8_10, 1.0.8-8.el9_4.1, 1.0.8-10.el9_5
Multicluster GlobalHub - update to 1.2.1
Migration Toolkit for Containers - update to 1.8.5
Red Hat Integration Camel-K - update to 1.10.9
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.7, 2.5.9, 2.6.7, 2.7.3, 2.7.4
OpenShift Service Mesh - addressed in versions 2.4.13, 2.4.14, 2.5.6, 2.5.7, 2.5.8, 2.6.5
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.8, 2.9.6, 2.10.7, 2.10.8, 2.11.4, 2.11.7, 2.12.2, 2.12.3
Red Hat OpenShift Dev Spaces - update to 3.17.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4
Dell EMC AppSync - update to 4.4.1.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.4.8, 4.5.5, 4.6.2
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.9
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.2
OpenShift Virtualization - addressed in versions 4.13.11, 4.15.9, 4.16.7, 4.17.3
Red Hat OpenShift Container Platform - addressed in versions 4.14.41, 4.14.46, 4.15.38, 4.16.44, 4.19.0
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
OpenShift Logging - addressed in versions 5.6.27, 5.8.17, 5.8.19, 5.8.20, 5.9.11, 5.9.14
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
Red Hat Ceph Storage - update to 8.1
RSA Authentication Manager - addressed in versions 8.4 Patch 10, 8.5 Patch 3
IBM License Metric Tool - update to 9.2.34
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins