F5-K000149130: Low severity F5 BIG-IP vulnerability
The c-ares function aresparsenaptrreply(), which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000149130?
The severity of F5-K000149130 is considered high due to its potential to allow unauthorized memory access.
How do I fix F5-K000149130?
To fix F5-K000149130, upgrade to the latest patched version of F5 BIG-IP that addresses this vulnerability.
What versions of F5 BIG-IP are affected by F5-K000149130?
F5-K000149130 affects F5 BIG-IP versions 15.1.0 to 15.1.10, 16.1.0 to 16.1.5, and 17.1.0 to 17.1.2.
What can happen if I do not address the vulnerability F5-K000149130?
If F5-K000149130 is not addressed, attackers could exploit this vulnerability to read sensitive memory content.
Is there a workaround for the vulnerability F5-K000149130?
No specific workaround is recommended for F5-K000149130; the primary mitigation is to apply the appropriate updates.