First published: Fri Oct 25 2024(Updated: )
CVE-2019-1000020 libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop. This attack appears to be exploitable via the victim opening a specially crafted ISO9660 file. CVE-2019-1000019 libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | >=17.1.0<=17.1.1 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.5 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-1000020 in F5 BIG-IP is considered high due to its potential to cause an infinite loop in the ISO9660 parser.
To fix CVE-2019-1000020 in F5 BIG-IP, you should upgrade to the latest version of the software provided by F5 that is not vulnerable.
F5-K000148255 affects F5 BIG-IP versions 17.1.0 to 17.1.1, 16.1.0 to 16.1.5, and 15.1.0 to 15.1.10.
CVE-2019-1000020 in F5 BIG-IP affects the ISO9660 parser, specifically in the functions read_CE() and parse_rockridge().
There is no official workaround for CVE-2019-1000020 in F5 BIG-IP; upgrading to a secure version is recommended.