ID

VAR-201906-1175


CVE

CVE-2019-11477


TITLE

Linux Kernel  Integer overflow vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2019-005619

DESCRIPTION

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff. Linux Kernel Exists in an integer overflow vulnerability.Service operation interruption (DoS) It may be in a state. A successful exploit could cause the targeted system to crash, resulting in a DoS condition. Proof-of-concept (PoC) code that demonstrates an exploit of this vulnerability is publicly available. Kernel.org has confirmed the vulnerability and released software updates. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2019:1484-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:1484 Issue date: 2019-06-17 CVE Names: CVE-2019-11477 CVE-2019-11478 CVE-2019-11479 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.3) - noarch, x86_64 Red Hat Enterprise Linux Server E4S (v. 7.3) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.3) - x86_64 Red Hat Enterprise Linux Server Optional E4S (v. 7.3) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 7.3) - x86_64 Red Hat Enterprise Linux Server TUS (v. 7.3) - noarch, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. While processing SACK segments, the Linux kernel's socket buffer (SKB) data structure becomes fragmented. To efficiently process SACK blocks, the Linux kernel merges multiple fragmented SKBs into one, potentially overflowing the variable holding the number of segments. A remote attacker could use this flaw to crash the Linux kernel by sending a crafted sequence of SACK segments on a TCP connection with small value of TCP MSS, resulting in a denial of service (DoS). (CVE-2019-11477) * Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service (CVE-2019-11478) * Kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service (CVE-2019-11479) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * THP: Race between MADV_DONTNEED and NUMA hinting node migration code (BZ#1698104) * [RHEL7] md_clear flag missing from /proc/cpuinfo on late microcode update (BZ#1712990) * [RHEL7] MDS mitigations are not enabled after double microcode update (BZ#1712995) * WARNING: CPU: 0 PID: 0 at kernel/jump_label.c:90 __static_key_slow_dec+0xa6/0xb0 (BZ#1713001) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1719123 - CVE-2019-11477 Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service 1719128 - CVE-2019-11478 Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service 1719129 - CVE-2019-11479 Kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.3): Source: kernel-3.10.0-514.66.2.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-514.66.2.el7.noarch.rpm kernel-doc-3.10.0-514.66.2.el7.noarch.rpm x86_64: kernel-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-devel-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.66.2.el7.x86_64.rpm kernel-devel-3.10.0-514.66.2.el7.x86_64.rpm kernel-headers-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-libs-3.10.0-514.66.2.el7.x86_64.rpm perf-3.10.0-514.66.2.el7.x86_64.rpm perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm python-perf-3.10.0-514.66.2.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.3): Source: kernel-3.10.0-514.66.2.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-514.66.2.el7.noarch.rpm kernel-doc-3.10.0-514.66.2.el7.noarch.rpm ppc64le: kernel-3.10.0-514.66.2.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-514.66.2.el7.ppc64le.rpm kernel-debug-3.10.0-514.66.2.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm kernel-debug-devel-3.10.0-514.66.2.el7.ppc64le.rpm kernel-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-514.66.2.el7.ppc64le.rpm kernel-devel-3.10.0-514.66.2.el7.ppc64le.rpm kernel-headers-3.10.0-514.66.2.el7.ppc64le.rpm kernel-tools-3.10.0-514.66.2.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm kernel-tools-libs-3.10.0-514.66.2.el7.ppc64le.rpm perf-3.10.0-514.66.2.el7.ppc64le.rpm perf-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm python-perf-3.10.0-514.66.2.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm x86_64: kernel-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-devel-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.66.2.el7.x86_64.rpm kernel-devel-3.10.0-514.66.2.el7.x86_64.rpm kernel-headers-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-libs-3.10.0-514.66.2.el7.x86_64.rpm perf-3.10.0-514.66.2.el7.x86_64.rpm perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm python-perf-3.10.0-514.66.2.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm Red Hat Enterprise Linux Server TUS (v. 7.3): Source: kernel-3.10.0-514.66.2.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-514.66.2.el7.noarch.rpm kernel-doc-3.10.0-514.66.2.el7.noarch.rpm x86_64: kernel-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debug-devel-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.66.2.el7.x86_64.rpm kernel-devel-3.10.0-514.66.2.el7.x86_64.rpm kernel-headers-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-libs-3.10.0-514.66.2.el7.x86_64.rpm perf-3.10.0-514.66.2.el7.x86_64.rpm perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm python-perf-3.10.0-514.66.2.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.3): x86_64: kernel-debug-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-514.66.2.el7.x86_64.rpm perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional E4S (v. 7.3): ppc64le: kernel-debug-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm kernel-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-514.66.2.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-514.66.2.el7.ppc64le.rpm perf-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-514.66.2.el7.ppc64le.rpm x86_64: kernel-debug-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-514.66.2.el7.x86_64.rpm perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional TUS (v. 7.3): x86_64: kernel-debug-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-514.66.2.el7.x86_64.rpm perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.66.2.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-11477 https://access.redhat.com/security/cve/CVE-2019-11478 https://access.redhat.com/security/cve/CVE-2019-11479 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/security/vulnerabilities/tcpsack 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXQfsINzjgjWX9erEAQjaUQ/8C6tiqftF16m5kCHgGT8J4hTBwf13ddVv nS9rspU7yqCtzQIJGyw07Dm4dnCBYKf4WH1jL7522Wrjdk23B4PWDkUm9JHvSjeJ dgT48tgCI9uIqtg1S6pIeEo78UMjKdJbuK4Zh8+v2udHAXrrTHd39/d+vQM5Ry+/ RgYRJFuzuv4Ed5ztARI7VyHHScQl8aDwxm4JZ1gRlDl80kTSANRx4pt5ZeHDZ+Uk izWZdpCSYo9aZEW1MZLLKdKyNatC5xvWo/j2HPoDYhpUIz+NALsa8kRtbzdcngRr L8jAhXGjtFHiQjGPH2u08Wr1K4KF8VRi3xYV+BGELGoG9AFbDaRY44khdRU4hTtp RrdCgeeeP+PhiYfw6jUeh77AfSndYTsEpt+HM1krZ2Zn18EnbFIkBA6jTx22WtB7 cEvHS4cZ09EexivrBNWuHiV8WlUsMRC/rMEkXfk/Z3gdntHaPoKMnubt8O6ULLzG 7848ptUHmRHN1lqi2ey+r2Itz7IVwq9xWB0+ls4thnJQxqcTUNM7YI0UQW0v3q8p pFkUbB2LlnZYcsniIR5gMiYZc7xfMidPKzWTUAi22BaifsBWMPX6gInszsV53rRM xTQfgYcClS0Dg7Hj2kLwKpwGm1IA8g65ljO1NooaAp5tlaUcO0TyZUDrIdWZ7M2M Htgga2C1aeg\xa3py -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . CVE-2019-3846, CVE-2019-10126 huangwen reported multiple buffer overflows in the Marvell wifi (mwifiex) driver, which a local user could use to cause denial of service or the execution of arbitrary code. CVE-2019-5489 Daniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz, Ari Trachtenberg, Jason Hennessey, Alex Ionescu, and Anders Fogh discovered that local users could use the mincore() system call to obtain sensitive information from other processes that access the same memory-mapped file. This update introduces a new sysctl value to control the minimal MSS (net.ipv4.tcp_min_snd_mss), which by default uses the formerly hard- coded value of 48. We recommend raising this to 536 unless you know that your network requires a lower value. CVE-2019-11486 Jann Horn of Google reported numerous race conditions in the Siemens R3964 line discipline. This module has therefore been disabled. CVE-2019-11599 Jann Horn of Google reported a race condition in the core dump implementation which could lead to a use-after-free. CVE-2019-11815 It was discovered that a use-after-free in the Reliable Datagram Sockets protocol could result in denial of service and potentially privilege escalation. This protocol module (rds) is not auto- loaded on Debian systems, so this issue only affects systems where it is explicitly loaded. CVE-2019-11833 It was discovered that the ext4 filesystem implementation writes uninitialised data from kernel memory to new extent blocks. A local user able to write to an ext4 filesystem and then read the filesystem image, for example using a removable drive, might be able to use this to obtain sensitive information. CVE-2019-11884 It was discovered that the Bluetooth HIDP implementation did not ensure that new connection names were null-terminated. A local user with CAP_NET_ADMIN capability might be able to use this to obtain sensitive information from the kernel stack. For the detailed security status of linux please refer to its security tracker page at: https://security-tracker.debian.org/tracker/linux Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl0H04lfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Tszw//R1zmUfrItTVMKsH3SlhMG/Nyd1efD/MaYwK/MXHv02BH56G3Th/W1uxh MEjyYTs7gE/UNyx6mr90G/BvymKNCqMEk5ooT7+xXcIgfBi+qvQW/YoBSOFi+Gai 58ofw0En+OQ4Fs1J95XRFjgegBitnsBumMxDcn2adKsbr7s8mKDaesENuXGe7sam Da8T6b0akCWK1i85JsQMG3OI661EdjosDHFHJyCVo8L1q3guYG11GPVlT/TI1ErN 68dVqLWq01Vn5TjKaUr6xeAHDMma+fKaHaitnxhmt06AcH/zQo4wDocQx8DOEWpE 6xBcCyABkKQ84iTKrFZKcnBDCwHaEcq6UytqIbkXIGpA0jRgaLzCNEOWt9GuENmt YoaxXwIi9RSMe8flyrWURGyWLrfJkh/Bk/P6WlpOCMSJmB9uXTnPxjMpfoMNqQjs BljbGqeN06dvFAq1fMzlqykbeHzDksHZ4pZizMNYqCNdQs3erm0rdyS55mN60o5/ SDIur1KokXi60zTwDPne1tyh00EP0liWyvh79u2/kaIazjbtTtoVYlyF5Wm/pu/r E46Mpv8pI7YIDNUVrtM/vLznqq+4BcVaqLBIVeMf+XAfqxJ5IrZ4ejaPvlP7hi4+ NwCQrSCaGk2nwBZr6Xs0qYVTsLLY9jkg8FUWPdH4ZEOFcGaWi3A=dgfy -----END PGP SIGNATURE----- . 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Bug Fix(es): * [HPE 8.0 Bug] nvme drive power button does not turn off drive (BZ#1700288) * RHEL8.0 - hw csum failure seen in dmesg and console (using mlx5/mlx4/Mellanox) (BZ#1700289) * RHEL8.0 - vfio-ap: add subsystem to matrix device to avoid libudev failures (kvm) (BZ#1700290) * [FJ8.1 Bug]: Make Fujitsu Erratum 010001 patch work on A64FX v1r0 (BZ#1700901) * [FJ8.0 Bug]: Fujitsu A64FX processor errata - panic by unknown fault (BZ#1700902) * RHEL 8.0 Snapshot 4 - nvme create-ns command hangs after creating 20 namespaces on Bolt (NVMe) (BZ#1701140) * [Cavium/Marvell 8.0 qed] Fix qed_mcp_halt() and qed_mcp_resume() (backporting bug) (BZ#1704184) * [Intel 8.1 Bug] PBF: Base frequency display fix (BZ#1706739) * [RHEL8]read/write operation not permitted to /sys/kernel/debug/gcov/reset (BZ#1708100) * RHEL8.0 - ISST-LTE:pVM:fleetwood:LPM:raylp85:After lpm seeing the console logs on the the lpar at target side (BZ#1708102) * RHEL8.0 - Backport support for software count cache flush Spectre v2 mitigation (BZ#1708112) * [Regression] RHEL8.0 - System crashed with one stress-ng-mremap stressor on Boston (kvm host) (BZ#1708617) * [intel ice Rhel 8 RC1] ethtool -A ethx causes interfaces to go down (BZ#1709433) 4. ========================================================================= Ubuntu Security Notice USN-4017-2 June 17, 2019 linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM - Ubuntu 12.04 ESM Summary: The system could be made to crash if it received specially crafted network traffic. (CVE-2019-11477) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: linux-image-3.13.0-171-generic 3.13.0-171.222 linux-image-3.13.0-171-generic-lpae 3.13.0-171.222 linux-image-3.13.0-171-lowlatency 3.13.0-171.222 linux-image-4.15.0-1047-azure 4.15.0-1047.51~14.04.1 linux-image-4.4.0-1046-aws 4.4.0-1046.50 linux-image-4.4.0-151-generic 4.4.0-151.178~14.04.1 linux-image-4.4.0-151-generic-lpae 4.4.0-151.178~14.04.1 linux-image-4.4.0-151-lowlatency 4.4.0-151.178~14.04.1 linux-image-aws 4.4.0.1046.47 linux-image-azure 4.15.0.1047.34 linux-image-generic 3.13.0.171.182 linux-image-generic-lpae 3.13.0.171.182 linux-image-generic-lpae-lts-xenial 4.4.0.151.133 linux-image-generic-lts-xenial 4.4.0.151.133 linux-image-lowlatency-lts-xenial 4.4.0.151.133 Ubuntu 12.04 ESM: linux-image-3.13.0-171-generic 3.13.0-171.222~12.04.1 linux-image-3.13.0-171-generic-lpae 3.13.0-171.222~12.04.1 linux-image-3.13.0-171-lowlatency 3.13.0-171.222~12.04.1 linux-image-3.2.0-141-generic 3.2.0-141.188 linux-image-generic 3.2.0.141.156 linux-image-generic-lpae-lts-trusty 3.13.0.171.159 linux-image-generic-lts-trusty 3.13.0.171.159 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. These packages include redhat-release-virtualization-host, ovirt-node, and rhev-hypervisor. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. The following packages have been upgraded to a later upstream version: redhat-release-virtualization-host (4.3.4), redhat-virtualization-host (4.3.4). # Advisory ###### ID: NFLX-2019-001 ###### Title: Linux and FreeBSD Kernel: Multiple TCP-based remote denial of service vulnerabilities ###### Release Date: 2019-06-17 ###### Severity: Critical ### Overview: Netflix has identified several TCP networking vulnerabilities in FreeBSD and Linux kernels. The vulnerabilities specifically relate to the minimum segment size (MSS) and TCP Selective Acknowledgement (SACK) capabilities. The most serious, dubbed _“SACK Panic_,” allows a remotely-triggered kernel panic on recent Linux kernels. There are patches that address most of these vulnerabilities. If patches can not be applied, certain mitigations will be effective. We recommend that affected parties enact one of those described below, based on their environment. __Fix:__ Apply the patch [PATCH_net_1_4.patch](2019-001/PATCH_net_1_4.patch). Additionally, versions of the Linux kernel up to, and including, 4.14 require a second patch [PATCH_net_1a.patch](2019-001/PATCH_net_1a.patch). __Workaround #1:__ Block connections with a low MSS using one of the supplied [filters](2019-001/block-low-mss/README.md). (The values in the filters are examples. You can apply a higher or lower limit, as appropriate for your environment.) Note that these filters may break legitimate connections which rely on a low MSS. Also, note that this mitigation is only effective if TCP probing is disabled (that is, the `net.ipv4.tcp_mtu_probing` sysctl is set to 0, which appears to be the default value for that sysctl). __Workaround #2:__ Disable SACK processing (`/proc/sys/net/ipv4/tcp_sack` set to 0). (Note that either workaround should be sufficient on its own. It is not necessary to apply both workarounds.) ### 2: [CVE-2019-11478](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11478): SACK Slowness (Linux < 4.15) or Excess Resource Usage (all Linux versions) __Description:__ It is possible to send a crafted sequence of SACKs which will fragment the TCP retransmission queue. On Linux kernels prior to 4.15, an attacker may be able to further exploit the fragmented queue to cause an expensive linked-list walk for subsequent SACKs received for that same TCP connection. __Fix:__ Apply the patch [PATCH_net_2_4.patch](2019-001/PATCH_net_2_4.patch) __Workaround #1:__ Block connections with a low MSS using one of the supplied [filters](2019-001/block-low-mss/README.md). (The values in the filters are examples. You can apply a higher or lower limit, as appropriate for your environment.) Note that these filters may break legitimate connections which rely on a low MSS. Also, note that this mitigation is only effective if TCP probing is disabled (that is, the `net.ipv4.tcp_mtu_probing` sysctl is set to 0, which appears to be the default value for that sysctl). __Workaround #2:__ Disable SACK processing (`/proc/sys/net/ipv4/tcp_sack` set to 0). (Note that either workaround should be sufficient on its own. It is not necessary to apply both workarounds.) ### 3: [CVE-2019-5599](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5599): SACK Slowness (FreeBSD 12 using the RACK TCP Stack) __Description:__ It is possible to send a crafted sequence of SACKs which will fragment the RACK send map. An attacker may be able to further exploit the fragmented send map to cause an expensive linked-list walk for subsequent SACKs received for that same TCP connection. __Workaround #1:__ Apply the patch [split_limit.patch](2019-001/split_limit.patch) and set the `net.inet.tcp.rack.split_limit` sysctl to a reasonable value to limit the size of the SACK table. __Workaround #2:__ Temporarily disable the RACK TCP stack. (Note that either workaround should be sufficient on its own. It is not necessary to apply both workarounds.) ### 4: [CVE-2019-11479](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11479): Excess Resource Consumption Due to Low MSS Values (all Linux versions) __Description:__ An attacker can force the Linux kernel to segment its responses into multiple TCP segments, each of which contains only 8 bytes of data. This drastically increases the bandwidth required to deliver the same amount of data. Further, it consumes additional resources (CPU and NIC processing power). This attack requires continued effort from the attacker and the impacts will end shortly after the attacker stops sending traffic. __Fix:__ Two patches [PATCH_net_3_4.patch](2019-001/PATCH_net_3_4.patch) and [PATCH_net_4_4.patch](2019-001/PATCH_net_4_4.patch) add a sysctl which enforces a minimum MSS, set by the `net.ipv4.tcp_min_snd_mss` sysctl. This lets an administrator enforce a minimum MSS appropriate for their applications. __Workaround:__ Block connections with a low MSS using one of the supplied [filters](2019-001/block-low-mss/README.md). (The values in the filters are examples. You can apply a higher or lower limit, as appropriate for your environment.) Note that these filters may break legitimate connections which rely on a low MSS. Also, note that this mitigation is only effective if TCP probing is disabled (that is, the `net.ipv4.tcp_mtu_probing` sysctl is set to 0, which appears to be the default value for that sysctl). ### Note: Good system and application coding and configuration practices (limiting write buffers to the necessary level, monitoring connection memory consumption via SO_MEMINFO, and aggressively closing misbehaving connections) can help to limit the impact of attacks against these kinds of vulnerabilities. ## Acknowledgments: Originally reported by Jonathan Looney. We thank Eric Dumazet for providing Linux fixes and support. We thank Bruce Curtis for providing the Linux filters. We thank Jonathan Lemon and Alexey Kodanev for helping to improve the Linux patches. We gratefully acknowledge the assistance of Tyler Hicks in testing fixes, refining the information about vulnerable versions, and providing assistance during the disclosure process. 6.6) - x86_64 3. Bug Fix(es): * MDS mitigations not enabled on Intel Skylake CPUs (BZ#1713026) * [RHEL6] md_clear flag missing from /proc/cpuinfo (BZ#1713029) * RHEL6 kernel does not disable SMT with mds=full,nosmt (BZ#1713044) 4

Trust: 2.43

sources: NVD: CVE-2019-11477 // JVNDB: JVNDB-2019-005619 // VULHUB: VHN-143127 // VULMON: CVE-2019-11477 // PACKETSTORM: 153323 // PACKETSTORM: 153337 // PACKETSTORM: 153315 // PACKETSTORM: 153327 // PACKETSTORM: 153543 // PACKETSTORM: 153329 // PACKETSTORM: 153320

AFFECTED PRODUCTS

vendor:redhatmodel:enterprise linuxscope:eqversion:5.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:15.0.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:18.10

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.20

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:12.1.0

Trust: 1.0

vendor:pulsesecuremodel:pulse policy securescope:eqversion: -

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:12.1.4

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:7.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:13.1.1

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:3.16.69

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:12.1.0

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.10

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:13.1.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:12.04

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:12.1.0

Trust: 1.0

vendor:redhatmodel:enterprise linux ausscope:eqversion:6.6

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:14.0.0

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:2.6.29

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:11.6.4

Trust: 1.0

vendor:redhatmodel:enterprise linux ausscope:eqversion:6.5

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:traffix signaling delivery controllerscope:gteversion:5.0.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:14.04

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:11.5.2

Trust: 1.0

vendor:redhatmodel:enterprise linux atomic hostscope:eqversion: -

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:14.0.0

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:6.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:15.0.0

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:8.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:12.1.4

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.1.11

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:11.6.4

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:16.04

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:14.0.0

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.9.182

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:15.0.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:18.04

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:15.0.0

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:7.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:12.1.0

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:7.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:12.1.4

Trust: 1.0

vendor:pulsesecuremodel:pulse secure virtual application delivery controllerscope:eqversion: -

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:11.5.2

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.15

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:11.6.4

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:traffix signaling delivery controllerscope:lteversion:5.1.0

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.19.52

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:14.0.0

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:3.17

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:12.1.0

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:12.1.4

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:12.1.4

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.4.182

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:15.0.0

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:19.04

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:11.6.4

Trust: 1.0

vendor:redhatmodel:enterprise mrgscope:eqversion:2.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:12.1.0

Trust: 1.0

vendor:ivantimodel:connect securescope:eqversion: -

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.14.127

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:13.1.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip link controllerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope: - version: -

Trust: 0.8

vendor:パルスセキュアmodel:pulse virtual application delivery controllerscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat virtualizationscope: - version: -

Trust: 0.8

vendor:パルスセキュアmodel:pulse connect securescope: - version: -

Trust: 0.8

vendor:f5model:big-ip fraud protection servicescope: - version: -

Trust: 0.8

vendor:linuxmodel:kernelscope: - version: -

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope: - version: -

Trust: 0.8

vendor:canonicalmodel:ubuntuscope: - version: -

Trust: 0.8

vendor:f5model:big-ip access policy managerscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linuxscope: - version: -

Trust: 0.8

vendor:f5model:big-ip analyticsscope: - version: -

Trust: 0.8

vendor:日立model:hitachi virtual storage platformscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux atomic hostscope: - version: -

Trust: 0.8

vendor:f5model:big-ip domain name systemscope: - version: -

Trust: 0.8

vendor:f5model:big-ip edge gatewayscope: - version: -

Trust: 0.8

vendor:f5model:traffix sdcscope: - version: -

Trust: 0.8

vendor:パルスセキュアmodel:pulse policy securescope: - version: -

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise mrgscope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2019-005619 // NVD: CVE-2019-11477

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-11477
value: HIGH

Trust: 1.0

security@ubuntu.com: CVE-2019-11477
value: HIGH

Trust: 1.0

NVD: CVE-2019-11477
value: HIGH

Trust: 0.8

VULHUB: VHN-143127
value: HIGH

Trust: 0.1

VULMON: CVE-2019-11477
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-11477
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-143127
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

security@ubuntu.com: CVE-2019-11477
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

nvd@nist.gov: CVE-2019-11477
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-143127 // VULMON: CVE-2019-11477 // JVNDB: JVNDB-2019-005619 // NVD: CVE-2019-11477 // NVD: CVE-2019-11477

PROBLEMTYPE DATA

problemtype:CWE-190

Trust: 1.1

problemtype:Integer overflow or wraparound (CWE-190) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-143127 // JVNDB: JVNDB-2019-005619 // NVD: CVE-2019-11477

THREAT TYPE

remote

Trust: 0.1

sources: PACKETSTORM: 153327

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-143127

PATCH

title:hitachi-sec-2020-303 Hitachi Storage Solution Security Informationurl:https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic

Trust: 0.8

title:Red Hat: Important: redhat-virtualization-host security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191594 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191485 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191484 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel-rt security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191480 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-4017-2

Trust: 0.1

title:Red Hat: Important: kernel-rt security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191487 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-4017-1

Trust: 0.1

title:Red Hat: Important: kernel security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191482 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel-rt security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191486 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191481 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191488 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191490 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191479 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191489 - Security Advisory

Trust: 0.1

title:Red Hat: Important: redhat-virtualization-host security and enhancement updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191699 - Security Advisory

Trust: 0.1

title:Red Hat: Important: kernel security, bug fix, and enhancement updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20191483 - Security Advisory

Trust: 0.1

title:Arch Linux Issues: url:https://vulmon.com/vendoradvisory?qidtp=arch_linux_issues&qid=CVE-2019-11477

Trust: 0.1

title:Amazon Linux AMI: ALAS-2019-1222url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2019-1222

Trust: 0.1

title:Arch Linux Advisories: [ASA-201906-12] linux-hardened: denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories&qid=ASA-201906-12

Trust: 0.1

title:Amazon Linux 2: ALAS2-2019-1222url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux2&qid=ALAS2-2019-1222

Trust: 0.1

title:Arch Linux Advisories: [ASA-201906-15] linux-zen: denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories&qid=ASA-201906-15

Trust: 0.1

title:Arch Linux Advisories: [ASA-201906-14] linux-lts: denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories&qid=ASA-201906-14

Trust: 0.1

title:Arch Linux Advisories: [ASA-201906-13] linux: denial of serviceurl:https://vulmon.com/vendoradvisory?qidtp=arch_linux_advisories&qid=ASA-201906-13

Trust: 0.1

title:IBM: Security Bulletin: Multiple Vulnerabilities in the Linux kernel affect the IBM FlashSystem models 840 and 900url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=b0e404260719b6ae04a48fa01fe4ff1d

Trust: 0.1

title:IBM: Security Bulletin: Multiple Vulnerabilities in the Linux kernel affect the IBM FlashSystem models V840 and V9000url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=17e4e6718a6d3a42ddb3642e1aa88aaf

Trust: 0.1

title:Huawei Security Advisories: Security Advisory - Integer Overflow Vulnerability in the Linux Kernel (SACK Panic)url:https://vulmon.com/vendoradvisory?qidtp=huawei_security_advisories&qid=a0ea5bac8e90e20896758ffe948339eb

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM MQ Appliance is affected by kernel vulnerabilities (CVE-2019-11479, CVE-2019-11478 and CVE-2019-11477)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=3abb37d34c3aab5be030484842a197cf

Trust: 0.1

title:IBM: IBM Security Bulletin: Linux Kernel as used by IBM QRadar SIEM is vulnerable to Denial of Service(CVE-2019-11477, CVE-2019-11478, CVE-2019-11479)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=ac66c3446fcbed558afc45a4f11875b9

Trust: 0.1

title:IBM: IBM Security Bulletin: Linux Kernel as used in IBM QRadar Network Packet Capture is vulnerable to denial of service (CVE-2019-11477, CVE-2019-11478, CVE-2019-11479)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=d4c7bbb6295709432116ceed6c8665d0

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM QRadar Network Security is affected by Linux kernel vulnerabilities (CVE-2019-11479, CVE-2019-11478, CVE-2019-11477)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=bae5fea992c13f587f4c457e2320189d

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM Cloud Kubernetes Service is affected by Linux Kernel security vulnerabilities (CVE-2019-11477, CVE-2019-11478, CVE-2019-11479)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=c19eb1501fe75f4801786c3ecf1bdfcd

Trust: 0.1

title:IBM: IBM Security Bulletin: Vulnerabilities in kernel affect Power Hardware Management Console (CVE-2019-11479,CVE-2019-11477 and CVE-2019-11478)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=1eb240b9222a3f8a10e0a63fa47e7f24

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM Security QRadar Packet Capture is vulnerable to Denial of Service (CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-3896)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=1282c74cfb8f7d86371051c0a3c9e604

Trust: 0.1

title:Siemens Security Advisories: Siemens Security Advisoryurl:https://vulmon.com/vendoradvisory?qidtp=siemens_security_advisories&qid=b013e0ae6345849ef39c81d52c9d45cf

Trust: 0.1

title:Citrix Security Bulletins: Citrix SD-WAN Security Updateurl:https://vulmon.com/vendoradvisory?qidtp=citrix_security_bulletins&qid=fa8566afabfba193549f3f15c0c81ff5

Trust: 0.1

title:Debian CVElist Bug Report Logs: linux-image-4.19.0-4-amd64: CVE-2019-11815url:https://vulmon.com/vendoradvisory?qidtp=debian_cvelist_bugreportlogs&qid=877a1ae1b4d7402bac3b3a0c44e3253b

Trust: 0.1

title:IBM: Security Bulletin: Vulnerabilities have been identified in OpenSSL and the Kernel shipped with the DS8000 Hardware Management Console (HMC)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=423d1da688755122eb2591196e4cc160

Trust: 0.1

title:Debian Security Advisories: DSA-4465-1 linux -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=1a396329c4647adcc53e47cd56d6ddad

Trust: 0.1

title:Oracle Linux Bulletins: Oracle Linux Bulletin - July 2019url:https://vulmon.com/vendoradvisory?qidtp=oracle_linux_bulletins&qid=767e8ff3a913d6c9b177c63c24420933

Trust: 0.1

title:Fortinet Security Advisories: TCP SACK panic attack- Linux Kernel Vulnerabilities- CVE-2019-11477, CVE-2019-11478 & CVE-2019-11479url:https://vulmon.com/vendoradvisory?qidtp=fortinet_security_advisories&qid=FG-IR-19-180

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM Netezza Host Management is affected by the vulnerabilities known as Intel Microarchitectural Data Sampling (MDS) and other Kernel vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=9b0697bf711f12539432f3ec83b074bf

Trust: 0.1

title:IBM: Security Bulletin: Multiple vulnerabilities affect IBM Cloud Object Storage Systems (February 2020v2)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=d9474066c07efdb84c4612586270078f

Trust: 0.1

title:IBM: IBM Security Bulletin: Linux Kernel vulnerabilities affect IBM Spectrum Protect Plus CVE-2019-10140, CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-13233, CVE-2019-13272, CVE-2019-14283, CVE-2019-14284, CVE-2019-15090, CVE-2019-15807, CVE-2019-15925url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=d9cd8f6d11c68af77f2f2bd27ca37bed

Trust: 0.1

title:IBM: IBM Security Bulletin: Multiple Security Vulnerabilities have been addressed in IBM Security Access Manager Applianceurl:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=800337bc69aa7ad92ac88a2adcc7d426

Trust: 0.1

title:Palo Alto Networks Security Advisory: url:https://vulmon.com/vendoradvisory?qidtp=palo_alto_networks_security_advisory&qid=e4153a9b76a5eea42e73bc20e968375b

Trust: 0.1

title:Palo Alto Networks Security Advisory: PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OSurl:https://vulmon.com/vendoradvisory?qidtp=palo_alto_networks_security_advisory&qid=57ed3d9f467472d630cb7b7dfca89570

Trust: 0.1

title:IBM: IBM Security Bulletin: Vyatta 5600 vRouter Software Patches – Release 1801-zaurl:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=8710e4e233940f7482a6adad4643a7a8

Trust: 0.1

title:IBM: IBM Security Bulletin: IBM Security Privileged Identity Manager is affected by multiple security vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=8580d3cd770371e2ef0f68ca624b80b0

Trust: 0.1

title:Siemens Security Advisories: Siemens Security Advisoryurl:https://vulmon.com/vendoradvisory?qidtp=siemens_security_advisories&qid=ec6577109e640dac19a6ddb978afe82d

Trust: 0.1

title:linux_hardening_arsenalurl:https://github.com/lucassbeiler/linux_hardening_arsenal

Trust: 0.1

title:tcp_sack_fixurl:https://github.com/sonoransun/tcp_sack_fix

Trust: 0.1

title:kpatch-sack-panicurl:https://github.com/fengjian/kpatch-sack-panic

Trust: 0.1

title:FFFFMurl:https://github.com/misanthropos/FFFFM

Trust: 0.1

title:docLinuxurl:https://github.com/hightemp/docLinux

Trust: 0.1

sources: VULMON: CVE-2019-11477 // JVNDB: JVNDB-2019-005619

EXTERNAL IDS

db:NVDid:CVE-2019-11477

Trust: 3.5

db:ICS CERTid:ICSA-19-253-03

Trust: 1.9

db:CERT/CCid:VU#905115

Trust: 1.9

db:PACKETSTORMid:153346

Trust: 1.1

db:PACKETSTORMid:154951

Trust: 1.1

db:OPENWALLid:OSS-SECURITY/2019/10/29/3

Trust: 1.1

db:OPENWALLid:OSS-SECURITY/2019/10/24/1

Trust: 1.1

db:OPENWALLid:OSS-SECURITY/2019/07/06/4

Trust: 1.1

db:OPENWALLid:OSS-SECURITY/2019/07/06/3

Trust: 1.1

db:OPENWALLid:OSS-SECURITY/2019/06/28/2

Trust: 1.1

db:OPENWALLid:OSS-SECURITY/2019/06/20/3

Trust: 1.1

db:PULSESECUREid:SA44193

Trust: 1.1

db:SIEMENSid:SSA-462066

Trust: 1.1

db:MCAFEEid:SB10287

Trust: 1.1

db:ICS CERTid:ICSA-23-234-01

Trust: 0.8

db:JVNid:JVNVU96001661

Trust: 0.8

db:JVNid:JVNVU93800789

Trust: 0.8

db:JVNDBid:JVNDB-2019-005619

Trust: 0.8

db:PACKETSTORMid:153329

Trust: 0.2

db:PACKETSTORMid:153320

Trust: 0.2

db:PACKETSTORMid:153327

Trust: 0.2

db:PACKETSTORMid:153315

Trust: 0.2

db:PACKETSTORMid:153323

Trust: 0.2

db:PACKETSTORMid:153424

Trust: 0.1

db:PACKETSTORMid:153324

Trust: 0.1

db:PACKETSTORMid:153316

Trust: 0.1

db:PACKETSTORMid:153317

Trust: 0.1

db:PACKETSTORMid:153321

Trust: 0.1

db:PACKETSTORMid:153318

Trust: 0.1

db:PACKETSTORMid:153430

Trust: 0.1

db:PACKETSTORMid:153325

Trust: 0.1

db:PACKETSTORMid:153322

Trust: 0.1

db:PACKETSTORMid:153328

Trust: 0.1

db:CNNVDid:CNNVD-201906-681

Trust: 0.1

db:BIDid:108801

Trust: 0.1

db:VULHUBid:VHN-143127

Trust: 0.1

db:VULMONid:CVE-2019-11477

Trust: 0.1

db:PACKETSTORMid:153337

Trust: 0.1

db:PACKETSTORMid:153543

Trust: 0.1

sources: VULHUB: VHN-143127 // VULMON: CVE-2019-11477 // JVNDB: JVNDB-2019-005619 // PACKETSTORM: 153323 // PACKETSTORM: 153337 // PACKETSTORM: 153315 // PACKETSTORM: 153327 // PACKETSTORM: 153543 // PACKETSTORM: 153329 // PACKETSTORM: 153320 // NVD: CVE-2019-11477

REFERENCES

url:https://github.com/netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md

Trust: 1.9

url:https://www.us-cert.gov/ics/advisories/icsa-19-253-03

Trust: 1.9

url:https://access.redhat.com/security/vulnerabilities/tcpsack

Trust: 1.5

url:https://nvd.nist.gov/vuln/detail/cve-2019-11477

Trust: 1.5

url:https://wiki.ubuntu.com/securityteam/knowledgebase/sackpanic

Trust: 1.2

url:https://access.redhat.com/errata/rhsa-2019:1699

Trust: 1.2

url:https://www.kb.cert.org/vuls/id/905115

Trust: 1.1

url:http://www.arubanetworks.com/assets/alert/aruba-psa-2020-010.txt

Trust: 1.1

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-kernel-en

Trust: 1.1

url:http://www.vmware.com/security/advisories/vmsa-2019-0010.html

Trust: 1.1

url:https://cert-portal.siemens.com/productcert/pdf/ssa-462066.pdf

Trust: 1.1

url:https://kb.pulsesecure.net/articles/pulse_security_advisories/sa44193

Trust: 1.1

url:https://psirt.global.sonicwall.com/vuln-detail/snwlid-2019-0006

Trust: 1.1

url:https://security.netapp.com/advisory/ntap-20190625-0001/

Trust: 1.1

url:https://support.f5.com/csp/article/k78234183

Trust: 1.1

url:https://www.synology.com/security/advisory/synology_sa_19_28

Trust: 1.1

url:http://packetstormsecurity.com/files/153346/kernel-live-patch-security-notice-lsn-0052-1.html

Trust: 1.1

url:http://packetstormsecurity.com/files/154951/kernel-live-patch-security-notice-lsn-0058-1.html

Trust: 1.1

url:https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=3b4929f65b0d8249f19a50245cd88ed1a2f78cff

Trust: 1.1

url:https://www.oracle.com/security-alerts/cpujan2020.html

Trust: 1.1

url:https://www.oracle.com/security-alerts/cpuoct2020.html

Trust: 1.1

url:http://www.openwall.com/lists/oss-security/2019/06/20/3

Trust: 1.1

url:http://www.openwall.com/lists/oss-security/2019/06/28/2

Trust: 1.1

url:http://www.openwall.com/lists/oss-security/2019/07/06/3

Trust: 1.1

url:http://www.openwall.com/lists/oss-security/2019/07/06/4

Trust: 1.1

url:http://www.openwall.com/lists/oss-security/2019/10/24/1

Trust: 1.1

url:http://www.openwall.com/lists/oss-security/2019/10/29/3

Trust: 1.1

url:https://access.redhat.com/errata/rhsa-2019:1594

Trust: 1.1

url:https://access.redhat.com/errata/rhsa-2019:1602

Trust: 1.1

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10287

Trust: 1.0

url:https://jvn.jp/vu/jvnvu93800789/

Trust: 0.8

url:http://jvn.jp/vu/jvnvu96001661/index.html

Trust: 0.8

url:https://www.kb.cert.org/vuls/id/905115/

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-23-234-01

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-11478

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-11479

Trust: 0.6

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2019-11479

Trust: 0.4

url:https://bugzilla.redhat.com/):

Trust: 0.4

url:https://access.redhat.com/security/team/key/

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2019-11477

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2019-11478

Trust: 0.4

url:https://access.redhat.com/security/team/contact/

Trust: 0.4

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.4

url:https://access.redhat.com/articles/11258

Trust: 0.3

url:https://kc.mcafee.com/corporate/index?page=content&amp;id=sb10287

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2019:1484

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-11599

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-11833

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-5489

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-9503

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-11884

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-11486

Trust: 0.1

url:https://www.debian.org/security/faq

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-9500

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10126

Trust: 0.1

url:https://security-tracker.debian.org/tracker/linux

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-11815

Trust: 0.1

url:https://www.debian.org/security/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-3846

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2019:1479

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-9213

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-9213

Trust: 0.1

url:https://usn.ubuntu.com/4017-2

Trust: 0.1

url:https://usn.ubuntu.com/4017-1

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10167

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10166

Trust: 0.1

url:https://access.redhat.com/articles/2974891

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-10166

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10168

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-10161

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-10168

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-10161

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-10167

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-5599

Trust: 0.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-11479):

Trust: 0.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-11478):

Trust: 0.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-5599):

Trust: 0.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-11477):

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-3896

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-3896

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2019:1489

Trust: 0.1

sources: VULHUB: VHN-143127 // JVNDB: JVNDB-2019-005619 // PACKETSTORM: 153323 // PACKETSTORM: 153337 // PACKETSTORM: 153315 // PACKETSTORM: 153327 // PACKETSTORM: 153543 // PACKETSTORM: 153329 // PACKETSTORM: 153320 // NVD: CVE-2019-11477

CREDITS

Red Hat

Trust: 0.4

sources: PACKETSTORM: 153323 // PACKETSTORM: 153315 // PACKETSTORM: 153543 // PACKETSTORM: 153320

SOURCES

db:VULHUBid:VHN-143127
db:VULMONid:CVE-2019-11477
db:JVNDBid:JVNDB-2019-005619
db:PACKETSTORMid:153323
db:PACKETSTORMid:153337
db:PACKETSTORMid:153315
db:PACKETSTORMid:153327
db:PACKETSTORMid:153543
db:PACKETSTORMid:153329
db:PACKETSTORMid:153320
db:NVDid:CVE-2019-11477

LAST UPDATE DATE

2024-11-07T20:03:21.587000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-143127date:2023-01-17T00:00:00
db:VULMONid:CVE-2019-11477date:2023-08-16T00:00:00
db:JVNDBid:JVNDB-2019-005619date:2023-08-24T05:29:00
db:NVDid:CVE-2019-11477date:2024-02-27T21:04:17.560

SOURCES RELEASE DATE

db:VULHUBid:VHN-143127date:2019-06-19T00:00:00
db:VULMONid:CVE-2019-11477date:2019-06-19T00:00:00
db:JVNDBid:JVNDB-2019-005619date:2019-06-25T00:00:00
db:PACKETSTORMid:153323date:2019-06-18T15:43:40
db:PACKETSTORMid:153337date:2019-06-19T17:12:34
db:PACKETSTORMid:153315date:2019-06-17T19:15:58
db:PACKETSTORMid:153327date:2019-06-18T15:44:10
db:PACKETSTORMid:153543date:2019-07-08T14:38:09
db:PACKETSTORMid:153329date:2019-06-18T15:50:02
db:PACKETSTORMid:153320date:2019-06-18T15:43:09
db:NVDid:CVE-2019-11477date:2019-06-19T00:15:12.640