CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2016-4545 F5 BIG-IP ASM TMM SSL Denial of Service Vulnerability (K48042976)

2017年8月19日 1101点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

On virtual servers with Secure Sockets Layer (SSL) profiles enabled, an SSL alert sent during the handshake may produce unnecessary logging and resource consumption on a BIG-IP system that is running 11.5.4 FINAL, possibly causing the Traffic Management Microkernel (TMM) to restart and produce a core file.

Affected Versions:
BIG-IP ASM 11.5.4

QID Detection Logic:
This authenticated QID checks for the vulnerable versions of F5 BIG-IP devices.

漏洞危害

When a Secure Sockets Layer (SSL) alert is sent during the handshake on a BIG-IP 11.5.4 base, the TMM may restart and produce a core file while logging SSL 'codec alert' messages to the /var/log/ltm file. The messages appear similar to the following example:
warning tmm[32354]: 01260009:4: Connection error: hud_ssl_handler:1131: codec alert (20)

解决方案

Customers are advised to refer to K48042976 for updates pertaining to this vulnerability.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

K48042976

0daybank

标签: 暂无
最后更新:2017年8月19日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me