F5-K000148252: Low severity F5 BIG-IQ Centralized Management vulnerability
Published Oct 25, 2024
·Updated
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile. TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Affected Software
1 affected componentFixes available
F5 BIG-IQ Centralized Management>=8.2.0<=8.4.0
8.4.1
Event History
Oct 25, 2024
Advisory Published
via F5·06:13 PM
Data Sourced
via F5·06:13 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of F5-K000148252?
The severity of F5-K000148252 is classified as MEDIUM.
2
How do I fix F5-K000148252?
To fix F5-K000148252, upgrade affected F5 products to their respective patched versions as specified in the advisory.
3
Which products are affected by F5-K000148252?
F5-K000148252 affects several products including BIG-IP Next Central Manager, BIG-IP Next SPK, and BIG-IQ Centralized Management among others.
4
What type of vulnerability is F5-K000148252?
F5-K000148252 is a Regular Expression Denial of Service (ReDoS) vulnerability.
5
How does F5-K000148252 exploit vulnerabilities in regular expressions?
F5-K000148252 exploits excessive backtracking during tarfile header parsing, allowing crafted tar archives to trigger the vulnerability.