iptables: buffer overflow in iptables-restore
Published Jul 12, 2019
4.2
MEDIUMCVSS 3.1
EPSS 1.81%
Description
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
iptables
Out of support scope
Red Hat Enterprise Linux 6
iptables
Out of support scope
Red Hat Enterprise Linux 7
iptables
Out of support scope
Red Hat Enterprise Linux 8
iptables
Not affected
Red Hat Enterprise Linux 9
iptables
Not affected
Red Hat OpenShift Container Platform 4
iptables
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | iptables | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | iptables | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | iptables | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | iptables | Not affected | n/a |
| Red Hat Enterprise Linux 9 | iptables | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | iptables | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw has been rated as having a security impact of Low because it requires unlikely circumstances to be able to be exploited. Red Hat Enterprise Linux 8 is not affected by this flaw, as the shipped versions of `iptables` already include the patch. Although Red Hat Enterprise Linux 6 and 7 are affected, successful exploitation is prevented by Stack Smashing Protection (SSP), reducing the impact to a denial of service. Note that this flaw is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 6 and 7. Red Hat Enterprise Linux 6 is in the Extended Life Phase of the support and maintenance life cycle; Red Hat Enterprise Linux 7 is now in Maintenance Support 2 Phase. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (7)
- https://0day.work/cve-2019-11360-bufferoverflow-in-iptables-restore-v1-8-2/ x_refsource_MISCExploitPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11360 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1927909 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3038 Advisory
- https://git.netfilter.org/iptables/commit/iptables/xshared.c?id=2ae1099a42e6a0f06de305ca13a842ac83d4683e x_refsource_CONFIRMPatchThird Party AdvisoryURL Repurposed
- https://nvd.nist.gov/vuln/detail/CVE-2019-11360
- https://www.cve.org/CVERecord?id=CVE-2019-11360
| Link | Providers | Tags |
|---|---|---|
| https://0day.work/cve-2019-11360-bufferoverflow-in-iptables-restore-v1-8-2/ | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-11360 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1927909 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3038 | Advisory | |
| https://git.netfilter.org/iptables/commit/iptables/xshared.c?id=2ae1099a42e6a0f06de305ca13a842ac83d4683e | x_refsource_CONFIRMPatchThird Party AdvisoryURL Repurposed | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11360 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-11360 |
Change history (0)
No recorded changes yet.