CVE Vulnerabilities

CVE-2019-3833

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Mar 14, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
OpenwsmanOpenwsman_project*2.6.9 (including)
Red Hat Enterprise Linux 7RedHatopenwsman-0:2.6.3-7.git4391e5c.el7*
Red Hat Enterprise Linux 8RedHatopenwsman-0:2.6.5-7.el8*
OpenwsmanUbuntubionic*
OpenwsmanUbuntucosmic*
OpenwsmanUbuntudevel*
OpenwsmanUbuntudisco*
OpenwsmanUbuntueoan*
OpenwsmanUbuntuesm-apps/bionic*
OpenwsmanUbuntuesm-apps/focal*
OpenwsmanUbuntuesm-apps/jammy*
OpenwsmanUbuntuesm-apps/noble*
OpenwsmanUbuntuesm-apps/xenial*
OpenwsmanUbuntufocal*
OpenwsmanUbuntugroovy*
OpenwsmanUbuntuhirsute*
OpenwsmanUbuntuimpish*
OpenwsmanUbuntujammy*
OpenwsmanUbuntukinetic*
OpenwsmanUbuntulunar*
OpenwsmanUbuntumantic*
OpenwsmanUbuntunoble*
OpenwsmanUbuntuoracular*
OpenwsmanUbuntuplucky*
OpenwsmanUbuntuquesting*
OpenwsmanUbuntutrusty*
OpenwsmanUbuntuxenial*

References