CVE-2019-1616
published 2019-03-11CVE-2019-1616: A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow…
PriorityP347high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.42%
82.3th percentile
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow, resulting in process crashes and a DoS condition on the device. MDS 9000 Series Multilayer Switches are affected running software versions prior to 6.2(25), 8.1(1b), 8.3(1). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected running software versions prior to 6.0(2)A8(10) and 7.0(3)I7(4). Nexus 3600 Platform Switches are affected running software versions prior to 7.0(3)F3(5) Nexus 7000 and 7700 Series Switches are affected running software versions prior to 6.2(22) and 8.2(3). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected running software versions prior to 7.0(3)F3(5). UCS 6200, 6300, and 6400 Fabric Interconnects are affected running software versions prior to 3.2(3j) and 4.0(2a).
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 6.2(25) | 6.2(25) |
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 8.1(1b) | 8.1(1b) |
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 8.3(1) | 8.3(1) |
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3500_platform_switches | >= unspecified < 6.0(2)A8(10) | 6.0(2)A8(10) |
| cisco | nexus_3500_platform_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3600_platform_switches | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 6.2(22) | 6.2(22) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 8.2(3) | 8.2(3) |
| cisco | nexus_9000_series_switches_in_standalone_nx-os_mode | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_9000_series_switches_in_standalone_nx-os_mode | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_9500_r-series_line_cards_and_fabric_modules | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nx-os | < 6.2\(22\) | 6.2\(22\) |
| cisco | nx-os | < 7.0\(3\)i4\(9\) | 7.0\(3\)i4\(9\) |
| cisco | nx-os | < 3.2\(3j\) | 3.2\(3j\) |
| cisco | nx-os | <= 6.0\(2\)a8 | — |
| cisco | nx-os | <= 7.0\(3\)i4 | — |
| cisco | nx-os | — | — |
| cisco | nx-os | >= 4.0 < 4.0\(2a\) | 4.0\(2a\) |
| cisco | nx-os | >= 5.2 < 6.2\(25\) | 6.2\(25\) |
| cisco | nx-os | >= 6.0\(2\)a8 < 6.0\(2\)a8\(10\) | 6.0\(2\)a8\(10\) |
| cisco | nx-os | >= 6.2 < 6.2\(22\) | 6.2\(22\) |
| cisco | nx-os | >= 7.0\(3\) < 7.0\(3\)i7\(4\) | 7.0\(3\)i7\(4\) |
| cisco | nx-os | >= 7.0\(3\)f1 < 7.0\(3\)f3\(3c\) | 7.0\(3\)f3\(3c\) |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qfp2-rcgq-9rpw: A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overf
ghsa_unreviewed·2022-05-13
CVE-2019-1616 [HIGH] CWE-119 GHSA-qfp2-rcgq-9rpw: A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overf
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow, resulting in process crashes and a DoS condition on the device. MDS 9000 Series Multilayer Switches are affected running software versions prior to 6.2(25), 8.1(1b), 8.3(1). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affect
Cisco
Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
vendor_cisco·2019-03-06·CVSS 8.6
CVE-2019-1616 [HIGH] CWE-20 Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition.
The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow, resulting in process crashes and a DoS condition on the device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
Cisco
Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1616 Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
CVE-2019-1616: Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow, resulting in process crashes and a DoS condition on the device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvh99066, CSCvj10176, CSCvj10178, CSCvh9
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13310 ImageMagick: memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c
bugzilla·2019-07-16·CVSS 6.5
CVE-2019-13310 [MEDIUM] CVE-2019-13310 ImageMagick: memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c
CVE-2019-13310 ImageMagick: memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1616
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730334]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/5f21230b657ccd65452dd3d94c5b5401ba691a2d
https://github.com/ImageMagick/ImageMagick6/commit/5982632109cad48bc6dab867298fdea4dea57c51
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates
Bugzilla
CVE-2019-13309 ImageMagick: memory leaks at AcquireMagickMemory due to mishandling the NoSuchImage error in CLIListOperatorImages
bugzilla·2019-07-16·CVSS 6.5
CVE-2019-13309 [MEDIUM] CVE-2019-13309 ImageMagick: memory leaks at AcquireMagickMemory due to mishandling the NoSuchImage error in CLIListOperatorImages
CVE-2019-13309 ImageMagick: memory leaks at AcquireMagickMemory due to mishandling the NoSuchImage error in CLIListOperatorImages
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1616
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730338]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick6/commit/5982632109cad48bc6dab867298fdea4dea57c51
https://github.com/ImageMagick/ImageMagick/commit/5f21230b657ccd65452dd3d94c5b5401ba691a2d
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.re
2019-03-11
Published