CVE Vulnerabilities

CVE-2019-9084

Divide By Zero

Published: Jun 07, 2019 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to conduct remote denial of service (disrupting certain business functions of the product).

Weakness

The product divides a value by zero.

Affected Software

NameVendorStart VersionEnd Version
HoteldruidDigitaldruid*2.3.1 (excluding)
HoteldruidUbuntubionic*
HoteldruidUbuntucosmic*
HoteldruidUbuntudevel*
HoteldruidUbuntudisco*
HoteldruidUbuntueoan*
HoteldruidUbuntuesm-apps/bionic*
HoteldruidUbuntuesm-apps/focal*
HoteldruidUbuntuesm-apps/jammy*
HoteldruidUbuntuesm-apps/noble*
HoteldruidUbuntuesm-apps/xenial*
HoteldruidUbuntufocal*
HoteldruidUbuntugroovy*
HoteldruidUbuntuhirsute*
HoteldruidUbuntuimpish*
HoteldruidUbuntujammy*
HoteldruidUbuntukinetic*
HoteldruidUbuntulunar*
HoteldruidUbuntumantic*
HoteldruidUbuntunoble*
HoteldruidUbuntuoracular*
HoteldruidUbuntuplucky*
HoteldruidUbuntuquesting*
HoteldruidUbuntutrusty*
HoteldruidUbuntuupstream*
HoteldruidUbuntuxenial*

References