CVE-2019-0052Improper Resource Shutdown or Release in Networks Junos OS

Severity
7.5HIGHNVD
EPSS
0.4%
top 42.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 24

Description

The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet. The packet is misinterpreted as a regular TCP packet which causes the processor to crash. This issue affects all SRX Series platforms that support URL-Filtering and have web-filtering enabled. Affected releases are Juniper Networks Junos OS: 12.3X48 versions prior to 12.3X48-D85 on SRX Series; 15.1X49 versions prior to 15.1X49-D181, 15.1X49-D190 on SRX Series; 17.3 versio

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5juniper_networks/junos_os8 versions+7
NVDjuniper/junos8 versions+7

Patches

🔴Vulnerability Details

1
GHSA
GHSA-q7jm-8335-rc9c: The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet2022-05-24

📋Vendor Advisories

1
Juniper
CVE-2019-0052: The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet. The packet is misinterpr2019-07-11

💬Community

2
Bugzilla
CVE-2018-11218 redis: Heap corruption in lua_cmsgpack.c2018-06-12
Bugzilla
CVE-2018-11219 redis: Integer overflow in lua_struct.c:b_unpack()2018-06-12
CVE-2019-0052 — Improper Resource Shutdown or Release | cvebase