Infinite loop in Go Net - CVE-2021-33194
Published: July 22, 2022
Vulnerability identifier: #VU65693
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33194
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop. A remote attacker can pass crafted ParseFragment input to the application, consume all available system resources and cause denial of service conditions.
Affected software
Go Net
Astronomer with IBM
ObjectScale
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Cloud Pak for Multicloud Management Monitoring
IBM Spectrum Protect Plus
IBM Netezza Performance Server
Operations Dashboard
IBM Edge Application Manager
IBM API Connect
Ubuntu
Fedora
golang-golang-x-net-dev (Ubuntu package)
adsys (Ubuntu package)
golang
IBM CICS TX Standard
IBM CICS TX Advanced
Astronomer with IBM
ObjectScale
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Cloud Pak for Multicloud Management Monitoring
IBM Spectrum Protect Plus
IBM Netezza Performance Server
Operations Dashboard
IBM Edge Application Manager
IBM API Connect
Ubuntu
Fedora
golang-golang-x-net-dev (Ubuntu package)
adsys (Ubuntu package)
golang
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2021-33194
Install updates from vendor's website.
Go Net - update to 0.0.0-20210520170846-37e1c6afe023
Astronomer with IBM - update to 1.0.1
QRadar Suite - update to 1.10.18.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM API Connect - addressed in versions 10.0.1.4, 2018.4.1.17
IBM Spectrum Protect Plus - update to 10.1.13
IBM Netezza Performance Server - update to 11.2.2.3
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
golang-golang-x-net-dev (Ubuntu package) - addressed in versions 1:0.0+git20160110.4fd4a9f-1ubuntu0.1~esm2, 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm2, 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm2
adsys (Ubuntu package) - addressed in versions 0.9.2~20.04.2ubuntu0.1+esm1, 2.0.11-0ubuntu1~16.04.4+esm2, 2.3.7-0ubuntu0.16.04.1+esm2, 3.0.3-0ubuntu1~18.04.2+esm2
ObjectScale - update to 1.4.0
golang - update to 1.18~rc1-2.fc36
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
Astronomer with IBM - update to 1.0.1
QRadar Suite - update to 1.10.18.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM API Connect - addressed in versions 10.0.1.4, 2018.4.1.17
IBM Spectrum Protect Plus - update to 10.1.13
IBM Netezza Performance Server - update to 11.2.2.3
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
golang-golang-x-net-dev (Ubuntu package) - addressed in versions 1:0.0+git20160110.4fd4a9f-1ubuntu0.1~esm2, 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm2, 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm2
adsys (Ubuntu package) - addressed in versions 0.9.2~20.04.2ubuntu0.1+esm1, 2.0.11-0ubuntu1~16.04.4+esm2, 2.3.7-0ubuntu0.16.04.1+esm2, 3.0.3-0ubuntu1~18.04.2+esm2
ObjectScale - update to 1.4.0
golang - update to 1.18~rc1-2.fc36
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
Related Security Bulletins
- Denial of service in Go Net
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM Operations Dashboard
- Denial of service in IBM API Connect
- Multiple vulnerabilities in IBM Netezza as a Service
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Dell ObjectScale
- Fedora 36 update for golang
- Multiple vulnerabilities in IBM Astronomer with IBM
- Ubuntu update for golang-golang-x-net-dev
- Ubuntu update for adsys