F5-K000135831: Medium severity F5 BIG-IP vulnerability
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000135831?
The F5-K000135831 vulnerability is classified as a denial of service flaw.
How do I fix F5-K000135831?
To fix F5-K000135831, upgrade affected BIG-IP or F5OS versions to the versions provided in the remediation.
Which versions of BIG-IP are affected by F5-K000135831?
BIG-IP versions 17.5.0 to 17.5.1.1, 17.1.0 to 17.1.2, and 16.1.0 to 16.1.6 are affected by F5-K000135831.
What products are impacted by F5-K000135831?
F5 BIG-IP and F5OS products are impacted by the F5-K000135831 vulnerability.
Is there a patch available for F5-K000135831?
Yes, a patch is available for F5-K000135831 in the recommended upgrade versions.