Buffer overflow in ManageOne - CVE-2019-5289

 

Buffer overflow in ManageOne - CVE-2019-5289

Published: November 15, 2019


Vulnerability identifier: #VU22790
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5289
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in the Gauss100 OLTP database. A remote attacker can construct invalid packets to attack the active and standby communication channels, trigger memory corruption and crash the database on the standby node.



Affected software

ManageOne

How to mitigate CVE-2019-5289

Install updates from vendor's website.

ManageOne - update to 6.5.1

External References

Related Security Bulletins