Resource management error in Moment - CVE-2016-4055
Published: October 14, 2019
Vulnerability identifier: #VU21762
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4055
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to an error in the "moment.duration()" function. A remote attacker can send a specially crafted input and cause regular expression denial of service via a long string.
Affected software
Moment
Tivoli Network Manager IP Edition
IBM Storage Scale System
Jazz Reporting Service
Tivoli Network Manager IP Edition
IBM Storage Scale System
Jazz Reporting Service
How to mitigate CVE-2016-4055
Install updates from vendor's website.
Moment - update to 2.11.2
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Storage Scale System - addressed in versions 5.2.0.0, 6.1.9.2
Jazz Reporting Service - update to 7.0.2 iFix021
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Storage Scale System - addressed in versions 5.2.0.0, 6.1.9.2
Jazz Reporting Service - update to 7.0.2 iFix021