F5-K000141051: Medium severity f5 traffix systems signaling delivery controller vulnerability
c-ares is a C library for asynchronous DNS requests. aresreadline() is used to parse local configuration files such as /etc/resolv.conf, /etc/nsswitch.conf, the HOSTALIASES file, and if using a c-ares version prior to 1.27.0, the /etc/hosts file. If any of these configuration files has an embedded NULL character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000141051?
The severity of F5-K000141051 is classified as critical.
How do I fix F5-K000141051?
To fix F5-K000141051, upgrade to the c-ares library version 1.27.0 or later.
What products are impacted by F5-K000141051?
F5-K000141051 affects F5 Traffix SDC versions from 5.1.0 to 5.2.0.
What files are involved in the vulnerability F5-K000141051?
The vulnerability F5-K000141051 involves local configuration files such as /etc/resolv.conf and /etc/hosts.
Is there a workaround for F5-K000141051?
There is no official workaround for F5-K000141051; upgrading is recommended.