SB2019092435 - Integer overflow in nfdump (Alpine package)
Published: September 24, 2019
Security Bulletin ID
SB2019092435
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2019-14459)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow within the Process_ipfix_template_withdraw() function in ipfix.c. A remote attacker can pass specially crafted data to the application, trigger integer overflow and crash the process.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=b8d192ba4ef5fa005e3a697714f667c79a8c01c2
- https://git.alpinelinux.org/aports/commit/?id=603173745d534fef8c500954f09b66dc512fe535
- https://git.alpinelinux.org/aports/commit/?id=34eaff89c07f1ff54a178e533eea071a315e1af8
- https://git.alpinelinux.org/aports/commit/?id=c754c0cdd91c787de14e9e4e394b26ec51045212
- https://git.alpinelinux.org/aports/commit/?id=631934be3ad64469888ffcb78c7c40c4b7d866d0
- https://git.alpinelinux.org/aports/commit/?id=8411819c2fbf4b8ede87ccaf2a3ffae0dfcc371f
- https://git.alpinelinux.org/aports/commit/?id=b11d34963eb3fed6ee588f008f97f1bc4cd113a7