CVE-2019-11360
published 2019-07-12CVE-2019-11360: A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a…
PriorityP419medium4.2CVSS 3.1
AVLACLPRHUIRSUCNINAH
EPSS
1.81%
76.2th percentile
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | iptables | < iptables 1.8.3-2 (bookworm) | iptables 1.8.3-2 (bookworm) |
| netfilter | iptables | — | — |
| netfilter | iptables | >= 0 < 1.8.3-2 | 1.8.3-2 |
| netfilter | iptables | >= 0 < 1.8.3-2 | 1.8.3-2 |
| netfilter | iptables | >= 0 < 1.8.3-2 | 1.8.3-2 |
| netfilter | iptables | >= 0 < 1.8.3-2 | 1.8.3-2 |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv4.2MEDIUM
vendor_debian4.2LOW
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g644-fvpx-hqm9: A buffer overflow in iptables-restore in netfilter iptables 1
ghsa_unreviewed·2022-05-24
CVE-2019-11360 [MEDIUM] CWE-119 GHSA-g644-fvpx-hqm9: A buffer overflow in iptables-restore in netfilter iptables 1
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
OSV
CVE-2019-11360: A buffer overflow in iptables-restore in netfilter iptables 1
osv·2019-07-12·CVSS 4.2
CVE-2019-11360 [MEDIUM] CVE-2019-11360: A buffer overflow in iptables-restore in netfilter iptables 1
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
Red Hat
iptables: buffer overflow in iptables-restore
vendor_redhat·2019-07-12·CVSS 4.2
CVE-2019-11360 [MEDIUM] CWE-120 iptables: buffer overflow in iptables-restore
iptables: buffer overflow in iptables-restore
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
A buffer overflow flaw was found in iptables-restore. This flaw allows a local attacker with sufficiently high privileges, such as root, to provide a specially crafted file, causing a program crash or potential code execution. The highest threat from this vulnerability is to system availability.
Statement: This flaw has been rated as having a security impact of Low because it requires unlikely circumstances to be able to be exploited. Red Hat Enterprise Linux 8 is not affected by this flaw, as the s
Debian
CVE-2019-11360: iptables - A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an atta...
vendor_debian·2019·CVSS 4.2
CVE-2019-11360 [MEDIUM] CVE-2019-11360: iptables - A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an atta...
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
Scope: local
bookworm: resolved (fixed in 1.8.3-2)
bullseye: resolved (fixed in 1.8.3-2)
forky: resolved (fixed in 1.8.3-2)
sid: resolved (fixed in 1.8.3-2)
trixie: resolved (fixed in 1.8.3-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://0day.work/cve-2019-11360-bufferoverflow-in-iptables-restore-v1-8-2/https://git.netfilter.org/iptables/commit/iptables/xshared.c?id=2ae1099a42e6a0f06de305ca13a842ac83d4683ehttps://0day.work/cve-2019-11360-bufferoverflow-in-iptables-restore-v1-8-2/https://git.netfilter.org/iptables/commit/iptables/xshared.c?id=2ae1099a42e6a0f06de305ca13a842ac83d4683e
2019-07-12
Published