cbcvebase.
CVE-2019-11360
published 2019-07-12

CVE-2019-11360: A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a…

PriorityP419medium4.2CVSS 3.1
AVLACLPRHUIRSUCNINAH
EPSS
1.81%
76.2th percentile
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianiptables< iptables 1.8.3-2 (bookworm)iptables 1.8.3-2 (bookworm)
netfilteriptables
netfilteriptables>= 0 < 1.8.3-21.8.3-2
netfilteriptables>= 0 < 1.8.3-21.8.3-2
netfilteriptables>= 0 < 1.8.3-21.8.3-2
netfilteriptables>= 0 < 1.8.3-21.8.3-2

CVSS provenance

nvdv3.14.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv4.2MEDIUM
vendor_debian4.2LOW
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.