Vulnerability Name:

CVE-2019-10153 (CCN-164897)

Assigned:2019-06-03
Published:2019-06-03
Updated:2023-02-02
Summary:A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.
CVSS v3 Severity:5.0 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L)
4.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
5.0 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L)
4.4 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-172
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-10153

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla - Bug 1716286
CVE-2019-10153 fence-agents: mis-handling of non-ASCII characters in guest comment fields

Source: secalert@redhat.com
Type: Issue Tracking, Third Party Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
fenceagents-cve201910153-dos(164897)

Source: CCN
Type: fence-agents GIT Repository
fence_rhevm: Changed Encoding to UTF-8 #255

Source: secalert@redhat.com
Type: Patch, Third Party Advisory
secalert@redhat.com

Source: CCN
Type: fence-agents GIT Repository
fence_rhevm: fix debug encoding issues #272

Source: secalert@redhat.com
Type: Patch, Third Party Advisory
secalert@redhat.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:clusterlabs:fence-agents:4.3.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201910153
    V
    CVE-2019-10153
    2022-09-02
    oval:org.opensuse.security:def:6344
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:4306
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:112216
    P
    fence-agents-4.10.0+git.1627556580.31443c15-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:4240
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:7295
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:69560
    P
    Security update for samba (Important)
    2021-11-19
    oval:org.opensuse.security:def:4167
    P
    Security update for webkit2gtk3 (Important)
    2021-11-03
    oval:org.opensuse.security:def:7273
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP3) (Important)
    2021-10-12
    oval:org.opensuse.security:def:105747
    P
    fence-agents-4.10.0+git.1627556580.31443c15-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:4154
    P
    Security update for ffmpeg (Important)
    2021-09-23
    oval:org.opensuse.security:def:4146
    P
    Security update for MozillaFirefox (Important)
    2021-08-19
    oval:org.opensuse.security:def:6452
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:14001
    P
    pcsc-ccid-1.4.14-1.42 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13979
    P
    libyaml-0-2-0.1.6-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:63385
    P
    xen-4.14.1_16-1.6 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62340
    P
    u-boot-rpiarm64-2021.01-5.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62819
    P
    libvdpau-devel-1.1.1-1.28 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62363
    P
    yubikey-manager-2.1.0-1.10 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63021
    P
    libpcp-devel-4.3.1-3.11.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62339
    P
    tpm2.0-tools-4.3.0-2.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:5087
    P
    Security update for djvulibre (Important)
    2021-08-05
    oval:org.opensuse.security:def:4209
    P
    Security update for spice-vdagent (Important)
    2021-08-05
    oval:org.opensuse.security:def:4205
    P
    Security update for caribou (Important)
    2021-07-20
    oval:org.opensuse.security:def:4278
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:4423
    P
    Security update for the Linux Kernel (Live Patch 8 for SLE 12 SP5) (Important)
    2021-06-18
    oval:org.opensuse.security:def:5065
    P
    Security update for libxml2 (Moderate)
    2021-06-18
    oval:org.opensuse.security:def:4427
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 12 SP5) (Important)
    2021-06-18
    oval:org.opensuse.security:def:6471
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:13341
    P
    libXp6-1.0.2-3.57 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13319
    P
    hplip-3.14.6-3.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13328
    P
    krb5-1.12.1-6.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13275
    P
    cpio-2.11-26.126 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:4412
    P
    Security update for the Linux Kernel (Live Patch 14 for SLE 12 SP5) (Important)
    2021-05-25
    oval:org.opensuse.security:def:4419
    P
    Security update for the Linux Kernel (Live Patch 7 for SLE 12 SP5) (Important)
    2021-05-25
    oval:org.opensuse.security:def:4192
    P
    Security update for fribidi (Important)
    2021-05-19
    oval:org.opensuse.security:def:69455
    P
    Security update for cifs-utils (Important)
    2021-04-30
    oval:org.opensuse.security:def:5026
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:4384
    P
    Security update for the Linux Kernel (Live Patch 8 for SLE 12 SP5) (Important)
    2021-04-07
    oval:org.opensuse.security:def:4387
    P
    Security update for the Linux Kernel (Live Patch 11 for SLE 12 SP5) (Important)
    2021-04-07
    oval:org.opensuse.security:def:4388
    P
    Security update for the Linux Kernel (Live Patch 12 for SLE 12 SP5) (Important)
    2021-04-07
    oval:org.opensuse.security:def:74274
    P
    Security update for openexr (Moderate)
    2021-04-07
    oval:org.opensuse.security:def:4381
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 12 SP5) (Important)
    2021-04-07
    oval:org.opensuse.security:def:6322
    P
    Security update for evolution-data-server (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:4290
    P
    Security update for the Linux Kernel (Important)
    2021-03-09
    oval:org.opensuse.security:def:6314
    P
    Security update for ImageMagick (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:4184
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:5048
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:4374
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:4367
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 12 SP5) (Important)
    2020-12-07
    oval:org.opensuse.security:def:13025
    P
    libmspack0-0.4-14.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13175
    P
    sblim-sfcb-1.4.8-17.3.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63159
    P
    libfpm_pb0-1.1.1-2.29 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13141
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13017
    P
    liblouis-data-2.6.4-6.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13047
    P
    libpng15-15-1.5.22-9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13250
    P
    python3-3.4.1-2.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13156
    P
    python-libxml2-2.9.4-46.20.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13094
    P
    libvpx1-1.3.0-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62540
    P
    libXinerama1-32bit-1.1.3-1.22 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12803
    P
    fence-agents-4.4.0+git.1558595666.5f79f9e9-3.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4349
    P
    Security update for the Linux Kernel (Important)
    2020-12-02
    oval:org.opensuse.security:def:4268
    P
    Security update for the Linux Kernel (Live Patch 7 for SLE 15) (Important)
    2020-12-02
    oval:org.opensuse.security:def:4247
    P
    Security update for the Linux Kernel (Important)
    2020-12-02
    oval:org.opensuse.security:def:4329
    P
    Security update for the Linux Kernel (Live Patch 11 for SLE 15) (Important)
    2020-12-02
    oval:org.opensuse.security:def:4252
    P
    Security update for the Linux Kernel (Live Patch 8 for SLE 15) (Important)
    2020-12-02
    oval:org.opensuse.security:def:6604
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66132
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:74148
    P
    Security update for ovmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6613
    P
    glib2-lang on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6546
    P
    DirectFB on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64096
    P
    Security update for gcc10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66086
    P
    Security update for fence-agents (Low)
    2020-12-01
    oval:org.opensuse.security:def:63846
    P
    Security update for apache2-mod_perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:72795
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:6622
    P
    groff on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6390
    P
    libjavascriptcoregtk-4_0-18 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66224
    P
    Security update for fence-agents (Low)
    2020-12-01
    oval:org.opensuse.security:def:6571
    P
    cpio on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64208
    P
    apache-commons-httpclient on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63952
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:65994
    P
    Security update for graphviz (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64054
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:72913
    P
    Security update for fence-agents (Low)
    2020-12-01
    oval:org.opensuse.security:def:63712
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:6635
    P
    hardlink on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6437
    P
    libsqlite3-0 on GA media (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20192037
    P
    RHSA-2019:2037: fence-agents security, bug fix, and enhancement update (Moderate)
    2019-08-06
    oval:com.ubuntu.disco:def:2019101530000000
    V
    CVE-2019-10153 on Ubuntu 19.04 (disco) - medium.
    2019-07-30
    oval:org.opensuse.security:def:109898
    P
    Security update for fence-agents (Low)
    2019-07-20
    oval:org.opensuse.security:def:91681
    P
    Security update for fence-agents (Low)
    2019-07-11
    oval:org.opensuse.security:def:91830
    P
    Security update for fence-agents (Low)
    2019-07-11
    oval:org.opensuse.security:def:98780
    P
    Security update for fence-agents (Low)
    2019-07-11
    oval:org.opensuse.security:def:125066
    P
    Security update for fence-agents (Low)
    2019-07-10
    oval:com.ubuntu.cosmic:def:2019101530000000
    V
    CVE-2019-10153 on Ubuntu 18.10 (cosmic) - medium.
    2019-06-04
    oval:com.ubuntu.bionic:def:2019101530000000
    V
    CVE-2019-10153 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-06-04
    oval:com.ubuntu.xenial:def:2019101530000000
    V
    CVE-2019-10153 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-06-04
    BACK
    clusterlabs fence-agents 4.3.3