CVE Vulnerabilities

CVE-2019-6638

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jul 03, 2019 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the restjavad process.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Big-ip_local_traffic_manager F5 14.0.0 (including) 14.0.0.5 (excluding)
Big-ip_local_traffic_manager F5 14.1.0 (including) 14.1.0.6 (excluding)

References