Infinite loop in Thrift - CVE-2019-0205

 

Infinite loop in Thrift - CVE-2019-0205

Published: November 6, 2019


Vulnerability identifier: #VU22565
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0205
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when processing user-supplied input. A remote attacker can pass malicious input to the application and consume all available system resources or cause denial of service conditions.


Affected software

Thrift
Gentoo Linux
openEuler
IBM Integration Bus
Netcool Operations Insight
IBM MQ Operator
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
JBoss Enterprise Application Platform
IBM Security Guardium
thrift-qt
perl-thrift
libthrift-java
fb303-java
thrift-debuginfo
python3-thrift
thrift-devel
thrift-debugsource
python3-fb303
fb303-devel
thrift-glib
fb303
thrift
libthrift-javadoc
IBM Cloud Pak for Watson AIOps
IBM supplied MQ Advanced container images
Red Hat Single Sign-On
Contrail Networking

How to mitigate CVE-2019-0205

Install updates from vendor's website.

Thrift - update to 0.13.0
JBoss Enterprise Application Platform - update to 7.2.7
thrift-qt - update to 0.10.0-3
perl-thrift - update to 0.10.0-3
libthrift-java - update to 0.10.0-3
fb303-java - update to 0.10.0-3
thrift-debuginfo - update to 0.10.0-3
python3-thrift - update to 0.10.0-3
thrift-devel - update to 0.10.0-3
thrift-debugsource - update to 0.10.0-3
python3-fb303 - update to 0.10.0-3
fb303-devel - update to 0.10.0-3
thrift-glib - update to 0.10.0-3
fb303 - update to 0.10.0-3
thrift - update to 0.10.0-3
libthrift-javadoc - update to 0.10.0-3
Netcool Operations Insight - update to 1.6.7
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
IBM Cloud Pak for Watson AIOps - update to 3.7.1
QRadar User Behavior Analytics - update to 4.1.9
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
Red Hat Single Sign-On - update to 7.3.7
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
Contrail Networking - update to 2011.L5

External References

Related Security Bulletins