Out-of-bounds write in Horizon DaaS and VMware ESXi - CVE-2019-5544

 

Out-of-bounds write in Horizon DaaS and VMware ESXi - CVE-2019-5544

Published: December 6, 2019 / Updated: February 20, 2022


Vulnerability identifier: #VU23432
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5544
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in OpenSLP. A remote attacker with network access to port 427 on an ESXi host or on any Horizon DaaS management appliance can overwrite the heap of the OpenSLP service, trigger out-of-bounds write and execute arbitrary code on the target system.

Note: This vulnerability affects Horizon DaaS 8.x


Affected software

Horizon DaaS
VMware ESXi
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Ubuntu
Fedora
libslp1 (Ubuntu package)
openslp
VCF over VxRail
SAN Volume Controller and Storwize Family

How to mitigate CVE-2019-5544

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi600-201912001, ESXi650-201912001, ESXi670-201912001
libslp1 (Ubuntu package) - update to 1.2.1-11ubuntu0.16.04.2
openslp - addressed in versions 2.0.0-22.fc30, 2.0.0-23.fc31
VCF over VxRail - update to 3.9.1
SAN Volume Controller and Storwize Family - addressed in versions 7.8.1.12, 8.2.1.11, 8.3.0.2, 8.3.1.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins