SB2021031411 - Denial of service in glibc implementation in F5 BIG-IP and F5OS



SB2021031411 - Denial of service in glibc implementation in F5 BIG-IP and F5OS

Published: March 14, 2021

Security Bulletin ID SB2021031411
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Out-of-bounds write (CVE-ID: CVE-2020-29573)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary within the sysdeps/i386/ldbl2mpn.c in the GNU C Library on x86  systems. A remote attacker can pass specially crafted data to the application that uses the vulnerable version of glibc and crash it.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.