QID 376580
Date Published: 2022-05-09
QID 376580: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) GNU C Library (glibc) Vulnerability (K24207649)
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
17.0.0
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.5
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially run arbitrary code and escalate their privileges on the system.
Solution
For more information about patch details please refer to K24207649
Vendor References
- K24207649 -
support.f5.com/csp/article/K24207649
CVEs related to QID 376580
Software Advisories
| Advisory ID | Software | Component | Link |
|---|