Buffer overflow in Apache Mina SSHD - CVE-2021-30129

 

Buffer overflow in Apache Mina SSHD - CVE-2021-30129

Published: September 29, 2021


Vulnerability identifier: #VU56931
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30129
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in the sshd-core of Apache Mina SSHD. A remote attacker can send specially crafted requests to the server, trigger buffer overflow and perform a denial of service (DoS) attack.


Affected software

Apache Mina SSHD
Oracle Communications Cloud Native Core Console
OSS Support Tools
JD Edwards EnterpriseOne Tools
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
JBoss Enterprise Application Platform
Wildfly Core
Fuse
IBM Business Automation Manager Open Editions
Oracle FLEXCUBE Universal Banking
Middleware Common Libraries and Tools
Oracle Banking Trade Finance
Oracle Banking Treasury Management
IBM Sterling Partner Engagement Manager
Oracle Global Lifecycle Management NextGen OUI Framework
Oracle Banking Payments
Oracle Retail Customer Management and Segmentation Foundation
openEuler
apache-sshd
apache-sshd-javadoc

How to mitigate CVE-2021-30129

Install updates from vendor's website.

Apache Mina SSHD - update to 2.7.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
JBoss Enterprise Application Platform - update to 7.4.2
IBM Business Automation Manager Open Editions - update to 8.0.3
Wildfly Core - update to 17.0.0
JD Edwards EnterpriseOne Tools - update to 9.2.7.3
Oracle Global Lifecycle Management NextGen OUI Framework - update to 13.9.4.2.10
Oracle FLEXCUBE Universal Banking - update to 14.3.0
apache-sshd - update to 2.2.0-2
apache-sshd-javadoc - update to 2.2.0-2
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
Fuse - update to 7.10.0

External References

Related Security Bulletins