QID 377616

Date Published: 2022-12-15

QID 377616: F5 BIG-IP Open Java Development Toolkit (OpenJDK) Vulnerability cve-2019-18197 (K10812540)

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.CVE-2019-18197

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
16.1.0 - 16.1.3
15.1.0 - 15.1.7
14.1.0 - 14.1.5
13.1.0 - 13.1.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

This vulnerability may lead to referencing memory after it has been freed and can have any number of adverse consequences, ranging from the corruption of valid data to the execution of arbitrary code, depending on the instantiation and timing of the flaw.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    For more information about patch details please refer to K10812540
    Vendor References

    CVEs related to QID 377616

    Software Advisories
    Advisory ID Software Component Link
    K10812540 URL Logo support.f5.com/csp/article/K10812540