QID 376745

Date Published: 2022-07-28

QID 376745: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) zlib Vulnerability (K21548854)

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.CVE-2018-25032

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

This vulnerability results in corrupted output, which leads to out-of-bound access, corrupting the memory and potentially causing the application to no longer respond.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    For more information about patch details please refer to K21548854
    Vendor References

    CVEs related to QID 376745

    Software Advisories
    Advisory ID Software Component Link
    K21548854 URL Logo support.f5.com/csp/article/K21548854