First published: Thu Nov 08 2018(Updated: )
keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
<2.0.7 | ||
=8.0 | ||
=7.0 | ||
=7.6 | ||
=7.6 | ||
=7.6 | ||
=7.0 | ||
Keepalived Keepalived | <2.0.7 | |
Debian Debian Linux | =8.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Eus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Workstation | =7.0 | |
redhat/keepalived | <2.0.9 | 2.0.9 |
debian/keepalived | 1:2.0.10-1 1:2.0.10-1+deb10u1 1:2.1.5-0.2+deb11u1 1:2.2.7-1 1:2.2.8-1 | |
ubuntu/keepalived | <1:1.3.9-1ubuntu0.18.04.2 | 1:1.3.9-1ubuntu0.18.04.2 |
ubuntu/keepalived | <1:1.3.9-1ubuntu1.1 | 1:1.3.9-1ubuntu1.1 |
ubuntu/keepalived | <1:1.2.7-1ubuntu1+ | 1:1.2.7-1ubuntu1+ |
ubuntu/keepalived | <2.0.9 | 2.0.9 |
ubuntu/keepalived | <1:1.2.24-1ubuntu0.16.04.2 | 1:1.2.24-1ubuntu0.16.04.2 |
https://github.com/acassen/keepalived/pull/961/commits/f28015671a4b04785859d1b4b1327b367b6a10e9
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19115 is a vulnerability in keepalived before version 2.0.7 that allows a heap-based buffer overflow when parsing HTTP status codes, leading to denial of service (DoS) or other unspecified impact.
CVE-2018-19115 has a severity score of 9.8, which is considered critical.
CVE-2018-19115 affects keepalived versions before 2.0.7.
Yes, the fix for CVE-2018-19115 is to update keepalived to version 2.0.7 or later.
You can find more information about CVE-2018-19115 at the following references: [CVE-2018-19115](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19115), [GitHub Pull Request](https://github.com/acassen/keepalived/pull/961), [Ubuntu Security Notice](https://ubuntu.com/security/notices/USN-3995-1).