Infinite loop in Thrift - CVE-2019-0205
Published: November 6, 2019
Vulnerability identifier: #VU22565
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0205
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when processing user-supplied input. A remote attacker can pass malicious input to the application and consume all available system resources or cause denial of service conditions.
Affected software
Thrift
Gentoo Linux
openEuler
IBM Integration Bus
Netcool Operations Insight
IBM MQ Operator
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
JBoss Enterprise Application Platform
IBM Security Guardium
thrift-qt
perl-thrift
libthrift-java
fb303-java
thrift-debuginfo
python3-thrift
thrift-devel
thrift-debugsource
python3-fb303
fb303-devel
thrift-glib
fb303
thrift
libthrift-javadoc
IBM Cloud Pak for Watson AIOps
IBM supplied MQ Advanced container images
Red Hat Single Sign-On
Contrail Networking
Gentoo Linux
openEuler
IBM Integration Bus
Netcool Operations Insight
IBM MQ Operator
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
JBoss Enterprise Application Platform
IBM Security Guardium
thrift-qt
perl-thrift
libthrift-java
fb303-java
thrift-debuginfo
python3-thrift
thrift-devel
thrift-debugsource
python3-fb303
fb303-devel
thrift-glib
fb303
thrift
libthrift-javadoc
IBM Cloud Pak for Watson AIOps
IBM supplied MQ Advanced container images
Red Hat Single Sign-On
Contrail Networking
How to mitigate CVE-2019-0205
Install updates from vendor's website.
Thrift - update to 0.13.0
JBoss Enterprise Application Platform - update to 7.2.7
thrift-qt - update to 0.10.0-3
perl-thrift - update to 0.10.0-3
libthrift-java - update to 0.10.0-3
fb303-java - update to 0.10.0-3
thrift-debuginfo - update to 0.10.0-3
python3-thrift - update to 0.10.0-3
thrift-devel - update to 0.10.0-3
thrift-debugsource - update to 0.10.0-3
python3-fb303 - update to 0.10.0-3
fb303-devel - update to 0.10.0-3
thrift-glib - update to 0.10.0-3
fb303 - update to 0.10.0-3
thrift - update to 0.10.0-3
libthrift-javadoc - update to 0.10.0-3
Netcool Operations Insight - update to 1.6.7
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
IBM Cloud Pak for Watson AIOps - update to 3.7.1
QRadar User Behavior Analytics - update to 4.1.9
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
Red Hat Single Sign-On - update to 7.3.7
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
Contrail Networking - update to 2011.L5
JBoss Enterprise Application Platform - update to 7.2.7
thrift-qt - update to 0.10.0-3
perl-thrift - update to 0.10.0-3
libthrift-java - update to 0.10.0-3
fb303-java - update to 0.10.0-3
thrift-debuginfo - update to 0.10.0-3
python3-thrift - update to 0.10.0-3
thrift-devel - update to 0.10.0-3
thrift-debugsource - update to 0.10.0-3
python3-fb303 - update to 0.10.0-3
fb303-devel - update to 0.10.0-3
thrift-glib - update to 0.10.0-3
fb303 - update to 0.10.0-3
thrift - update to 0.10.0-3
libthrift-javadoc - update to 0.10.0-3
Netcool Operations Insight - update to 1.6.7
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
IBM Cloud Pak for Watson AIOps - update to 3.7.1
QRadar User Behavior Analytics - update to 4.1.9
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
Red Hat Single Sign-On - update to 7.3.7
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
Contrail Networking - update to 2011.L5
External References
- http://mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3CVI1PR0101MB2142E0EA19F582429C3AEBCBB1920%40VI1PR0101MB2142.eurprd01.prod.exchangelabs.com%3E
- https://lists.apache.org/thread.html/07bd68ad237a5d513751d6d2731a8828f902c738ea57d85c1a72bad3@%3Cdev.thrift.apache.org%3E
- https://lists.apache.org/thread.html/0d058e1bfd11727c4f2e2adf4b6e403a47c38e22431ab20066a1ac79@%3Cdev.thrift.apache.org%3E
- https://lists.apache.org/thread.html/3dfa054b89274c9109c26ed1843ca15a14c03786f4016d26773878ae@%3Cdev.thrift.apache.org%3E
- https://lists.apache.org/thread.html/928cae83d20d8d8196c26118f7084aa37573e1d31162381fb9454fb5@%3Cdev.thrift.apache.org%3E
- https://lists.apache.org/thread.html/a9669756befaeb0f8e08766d3f4d410a0fce85da3a570506f71f0b67@%3Cdev.thrift.apache.org%3E
Related Security Bulletins
- Denial of service in Apache Thrift
- Multiple vulnerabilities in JBoss Enterprise Application Platform
- Gentoo update for Apache Thrift
- IBM Security Guardium update for Apache Thrift
- Multiple vulnerabilities in Juniper Networks Contrail Networking
- Multiple vulnerabilities in IBM Integration Bus
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Application Performance Management products
- openEuler 20.03 LTS SP1 update for thrift
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in Red Hat Single Sign-On 7.3