Infinite loop in Go Net - CVE-2021-33194

 

Infinite loop in Go Net - CVE-2021-33194

Published: July 22, 2022


Vulnerability identifier: #VU65693
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33194
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop. A remote attacker can pass crafted ParseFragment  input to the application, consume all available system resources and cause denial of service conditions.


Affected software

Go Net
Astronomer with IBM
ObjectScale
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Cloud Pak for Multicloud Management Monitoring
IBM Spectrum Protect Plus
IBM Netezza Performance Server
Operations Dashboard
IBM Edge Application Manager
IBM API Connect
Ubuntu
Fedora
golang-golang-x-net-dev (Ubuntu package)
adsys (Ubuntu package)
golang
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2021-33194

Install updates from vendor's website.

Go Net - update to 0.0.0-20210520170846-37e1c6afe023
Astronomer with IBM - update to 1.0.1
QRadar Suite - update to 1.10.18.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM API Connect - addressed in versions 10.0.1.4, 2018.4.1.17
IBM Spectrum Protect Plus - update to 10.1.13
IBM Netezza Performance Server - update to 11.2.2.3
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
golang-golang-x-net-dev (Ubuntu package) - addressed in versions 1:0.0+git20160110.4fd4a9f-1ubuntu0.1~esm2, 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm2, 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm2
adsys (Ubuntu package) - addressed in versions 0.9.2~20.04.2ubuntu0.1+esm1, 2.0.11-0ubuntu1~16.04.4+esm2, 2.3.7-0ubuntu0.16.04.1+esm2, 3.0.3-0ubuntu1~18.04.2+esm2
ObjectScale - update to 1.4.0
golang - update to 1.18~rc1-2.fc36
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins