keepalived before 2.0.7 has a heap-based buffer overflow when parsing...
Vulnerability Description
keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-19115
Credits & Attribution
No credits recorded in the NVD database.
References
- https://security.gentoo.org/glsa/201903-01
- https://lists.debian.org/debian-lts-announce/2018/11/msg00034.html
- https://bugzilla.suse.com/show_bug.cgi?id=1015141
- https://github.com/acassen/keepalived/pull/961/commits/f28015671a4b04785859d1b4b1327b367b6a10e9
- https://github.com/acassen/keepalived/pull/961
- https://access.redhat.com/errata/RHSA-2019:0022
- https://usn.ubuntu.com/3995-1/
- https://usn.ubuntu.com/3995-2/
- https://access.redhat.com/errata/RHSA-2019:1792
- https://access.redhat.com/errata/RHSA-2019:1945
More from keepalived
View All →Affected Vendor
keepalived
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.