F5-K000139643: Medium severity f5 big-ip vulnerability
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000139643?
The severity of F5-K000139643 is classified as moderate due to the potential for memory exhaustion and crashes.
How do I fix F5-K000139643?
To fix F5-K000139643, upgrade node-tar to version 6.2.1 or later in your affected F5 BIG-IP versions.
Which F5 products are affected by F5-K000139643?
F5-K000139643 affects F5 BIG-IP (iRulesLX/iAppsLX) versions 15.1.0 to 15.1.10, 16.1.0 to 16.1.4, and 17.1.0 to 17.1.1.
What type of vulnerability is F5-K000139643?
F5-K000139643 is a denial of service vulnerability caused by unrestricted folder creation limits.
Can F5-K000139643 be exploited remotely?
Yes, F5-K000139643 can be exploited remotely by an attacker generating a high number of sub-folders.