F5-K64119434: Medium severity F5 BIG-IP vulnerability
In the GNU C Library (aka glibc or libc6) before 2.28, parseregexp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K64119434?
The severity of F5-K64119434 is high due to its potential to cause denial of service or incorrect results in applications.
How do I fix F5-K64119434?
Fix F5-K64119434 by upgrading to a patched version of the affected F5 products, specifically to versions above 17.5.1, 16.1.6, 15.1.10, or 8.4.1 for BIG-IQ Centralized Management.
What types of denial of service attacks are associated with F5-K64119434?
F5-K64119434 can lead to a denial of service through assertion failures and application crashes during regular-expression parsing.
Which versions of F5 BIG-IP are affected by F5-K64119434?
F5-K64119434 affects F5 BIG-IP versions 17.5.0, 17.1.0 to 17.1.2, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10.
Is F5 Traffix SDC safe from F5-K64119434?
F5 Traffix SDC version 5.2.0 is affected by F5-K64119434 and should be evaluated for necessary updates.