Out-of-bounds write in Horizon DaaS and VMware ESXi - CVE-2019-5544
Published: December 6, 2019 / Updated: February 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in OpenSLP. A remote attacker with network access to port 427 on an ESXi host or on any Horizon DaaS management appliance can overwrite the heap of the OpenSLP service, trigger out-of-bounds write and execute arbitrary code on the target system.
Note: This vulnerability affects Horizon DaaS 8.x
Affected software
VMware ESXi
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Ubuntu
Fedora
libslp1 (Ubuntu package)
openslp
VCF over VxRail
SAN Volume Controller and Storwize Family
How to mitigate CVE-2019-5544
libslp1 (Ubuntu package) - update to 1.2.1-11ubuntu0.16.04.2
openslp - addressed in versions 2.0.0-22.fc30, 2.0.0-23.fc31
VCF over VxRail - update to 3.9.1
SAN Volume Controller and Storwize Family - addressed in versions 7.8.1.12, 8.2.1.11, 8.3.0.2, 8.3.1.0
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in VMware ESXi and Horizon DaaS
- Red Hat update for openslp
- Red Hat update for openslp
- Gentoo update for OpenSLP
- Ubuntu update for openslp-dfsg
- Remote code execution in Dell EMC VCF over VxRail
- Out-of-bounds write in IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products
- Fedora 31 update for openslp
- Fedora 30 update for openslp