#VU64153 Out-of-bounds read in Istio


Published: 2022-06-10 | Updated: 2022-07-27

Vulnerability identifier: #VU64153

Vulnerability risk: Medium

CVSSv3.1: 5.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-31045

CWE-ID: CWE-125

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Istio
Web applications / Other software

Vendor: Istio

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the Ill-formed headers. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.

Mitigation

Install updates from vendor's website.

Note, the 1.14.2 or 1.13.6 versions are affected by this vulnerability due to process issues on the vendor's side.

Vulnerable software versions

Istio: 0.1 - 1.14.2


External links
http://github.com/istio/istio/security/advisories/GHSA-xwx5-5c9g-x68x
http://istio.io/latest/news/security/istio-security-2022-05
http://istio.io/latest/news/security/istio-security-2022-006


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability