Improper Handling of Length Parameter Inconsistency vulnerability in Bitdefender Update Server (VA-10144)
Published Apr 7, 2022
7.5
HIGHCVSS 3.1
EPSS 1.25%
Description
Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276. Bitdefender GravityZone versions prior to 26.4-1. Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.171. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.1.111.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<6.2.21.171
- Version
-
- Version unspecifiedStatusaffectedConstraints<7.4.1.111
- Version
-
- Version unspecifiedStatusaffectedConstraints<26.4-1
- Version
-
- Version unspecifiedStatusaffectedConstraints<3.4.0.276
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Bitdefender | Endpoint Security Tools for Linux | n/a |
| ||||||
| Bitdefender | Endpoint Security Tools for Windows | n/a |
| ||||||
| Bitdefender | GravityZone | n/a |
| ||||||
| Bitdefender | Update Server | n/a |
|
- < 6.2.21.171
- < 7.4.1.111
- < 26.4-1
- < 3.4.0.276
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
An automatic update to the following product version fixes the issues:
Bitdefender Update Server version3.4.0.276. Bitdefender GravityZone version 26.4-1. Bitdefender Endpoint Security Tools for Linux version 6.2.21.171. Bitdefender Endpoint Security Tools for Windows version 7.4.1.111.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15763 Advisory
- https://www.bitdefender.com/support/security-advisories/improper-handling-of-length-parameter-inconsistency-vulnerability-in-bitdefender-update-server-va-10144 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15763 | Advisory | |
| https://www.bitdefender.com/support/security-advisories/improper-handling-of-length-parameter-inconsistency-vulnerability-in-bitdefender-update-server-va-10144 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.