Executive Summary

Informations
Name CVE-2019-0010 First vendor Publication 2019-01-15
Vendor Cve Last vendor Modification 2020-08-24

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 7.5
Base Score 7.5 Environmental Score 7.5
impact SubScore 3.6 Temporal Score 7.5
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an indication of memory buffer exhaustion -- due to the receipt of crafted HTTP traffic. Each crafted HTTP packet inspected by UTM consumes mbufs which can be identified through the following log messages: all_logs.0:Jun 8 03:25:03 srx1 node0.fpc4 : SPU3 jmpi mbuf stall 50%. all_logs.0:Jun 8 03:25:13 srx1 node0.fpc4 : SPU3 jmpi mbuf stall 51%. all_logs.0:Jun 8 03:25:24 srx1 node0.fpc4 : SPU3 jmpi mbuf stall 52%. ... Eventually the system runs out of mbufs and the system crashes (fails over) with the error "mbuf exceed". This issue only occurs when HTTP AV inspection is configured. Devices configured for Web Filtering alone are unaffected by this issue. Affected releases are Junos OS on SRX Series: 12.1X46 versions prior to 12.1X46-D81; 12.3X48 versions prior to 12.3X48-D77; 15.1X49 versions prior to 15.1X49-D101, 15.1X49-D110.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0010

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-770 Allocation of Resources Without Limits or Throttling

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 39

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/106535
CONFIRM https://kb.juniper.net/JSA10910

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
Date Informations
2024-02-02 01:58:52
  • Multiple Updates
2024-02-01 12:16:19
  • Multiple Updates
2023-09-05 12:56:47
  • Multiple Updates
2023-09-05 01:16:00
  • Multiple Updates
2023-09-02 12:56:05
  • Multiple Updates
2023-09-02 01:16:17
  • Multiple Updates
2023-08-12 12:59:53
  • Multiple Updates
2023-08-12 01:15:34
  • Multiple Updates
2023-08-11 12:53:48
  • Multiple Updates
2023-08-11 01:16:00
  • Multiple Updates
2023-08-06 12:52:13
  • Multiple Updates
2023-08-06 01:15:31
  • Multiple Updates
2023-08-04 12:52:27
  • Multiple Updates
2023-08-04 01:15:40
  • Multiple Updates
2023-07-14 12:52:27
  • Multiple Updates
2023-07-14 01:15:38
  • Multiple Updates
2023-03-29 01:53:51
  • Multiple Updates
2023-03-28 12:15:57
  • Multiple Updates
2022-10-11 12:46:55
  • Multiple Updates
2022-10-11 01:15:36
  • Multiple Updates
2020-09-03 01:24:29
  • Multiple Updates
2020-05-23 02:20:32
  • Multiple Updates
2019-10-10 05:20:50
  • Multiple Updates
2019-04-16 12:09:25
  • Multiple Updates
2019-02-14 12:08:35
  • Multiple Updates
2019-01-16 17:19:09
  • Multiple Updates
2019-01-16 00:19:09
  • First insertion