CVE Vulnerabilities

CVE-2019-9084

Divide By Zero

Published: Jun 07, 2019 | Modified: Jul 01, 2019
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to conduct remote denial of service (disrupting certain business functions of the product).

Weakness

The product divides a value by zero.

Affected Software

Name Vendor Start Version End Version
Hoteldruid Digitaldruid * 2.3.1 (excluding)
Hoteldruid Ubuntu bionic *
Hoteldruid Ubuntu cosmic *
Hoteldruid Ubuntu devel *
Hoteldruid Ubuntu disco *
Hoteldruid Ubuntu eoan *
Hoteldruid Ubuntu esm-apps/bionic *
Hoteldruid Ubuntu esm-apps/xenial *
Hoteldruid Ubuntu focal *
Hoteldruid Ubuntu groovy *
Hoteldruid Ubuntu hirsute *
Hoteldruid Ubuntu impish *
Hoteldruid Ubuntu jammy *
Hoteldruid Ubuntu kinetic *
Hoteldruid Ubuntu lunar *
Hoteldruid Ubuntu mantic *
Hoteldruid Ubuntu noble *
Hoteldruid Ubuntu oracular *
Hoteldruid Ubuntu trusty *
Hoteldruid Ubuntu upstream *
Hoteldruid Ubuntu xenial *

References