NULL pointer dereference in crypto - CVE-2020-29652

 

NULL pointer dereference in crypto - CVE-2020-29652

Published: November 21, 2022


Vulnerability identifier: #VU69449
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29652
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when processing an authentication request message for the “gssapi-with-mic” method. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

crypto
ObjectScale
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Storage Ceph
IBM Cloud Pak System
Splunk Enterprise
IBM MQ Operator
OpenShift Virtualization
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2020-29652

Install updates from vendor's website.

crypto - update to 0.0.0-20201216223049-8b5274cf687f
ObjectScale - update to 1.3.0
IBM Cloud Pak System - update to 2.3.3.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.1
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.4.0
OpenShift Virtualization - update to 4.8.0
Storage Ceph - update to 7.1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5

External References

Related Security Bulletins