QID 376066

Date Published: 2021-11-18

QID 376066: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) GNU C Library (glibc) Vulnerability (K52494142)

The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.CVE-2016-10228

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
16.0.0 - 16.0.1
15.1.0 - 15.1.3
14.1.0 - 14.1.4
13.1.0 - 13.1.4
12.1.0 - 12.1.6
11.6.1 - 11.6.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

An attacker can exploit this vulnerability by crafting a sequence of invalid multi-byte input to an application using the iconv program and causing the application to enter an infinite loop, leading to a denial-of-service (DoS).

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The vendor has released patch, for more information please visit: K52494142
    Vendor References

    CVEs related to QID 376066

    Software Advisories
    Advisory ID Software Component Link
    K52494142 URL Logo support.f5.com/csp/article/K52494142