QID 377669
Date Published: 2022-11-14
QID 377669: F5 BIG-IP Bind vulnerability cve-2022-38177 (K27155546)
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.CVE-2022-38177
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.7
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named terminates for lack of resources.
Solution
For more information about patch details please refer to K27155546
Vendor References
- K27155546 -
support.f5.com/csp/article/K27155546
CVEs related to QID 377669
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K27155546 |
|