NULL pointer dereference in LibOFX - CVE-2019-9656

 

NULL pointer dereference in LibOFX - CVE-2019-9656

Published: March 11, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36079
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9656
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dreference error in file lib/ofx_sgml.cpp, as demonstrated by ofxdump. A remote attacker can perform a denial of service (DoS) attack.


Affected software

LibOFX
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Fedora
SUSE Linux Enterprise Workstation Extension 12
Ubuntu
libofx
libofx-debuginfo
libofx-debugsource
libofx-devel
libofx6-debuginfo
libofx6
libofx-dev (Ubuntu package)
libofx6 (Ubuntu package)
ofx (Ubuntu package)

How to mitigate CVE-2019-9656

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

libofx - update to 0.9.9-3.el7
libofx-debuginfo - update to 0.9.9-3.10.1
libofx-debugsource - update to 0.9.9-3.10.1
libofx-devel - update to 0.9.9-3.10.1
libofx - update to 0.9.9-3.10.1
libofx6-debuginfo - update to 0.9.9-3.10.1
libofx6 - update to 0.9.9-3.10.1
libofx-dev (Ubuntu package) - update to 1:0.9.10-1+deb8u2build0.16.04.1
libofx6 (Ubuntu package) - update to 1:0.9.10-1+deb8u2build0.16.04.1
ofx (Ubuntu package) - update to 1:0.9.10-1+deb8u2build0.16.04.1

External References

Related Security Bulletins