PT-2018-17002 · F5 · F5 Big-Ip Pem
Published
2018-04-13
·
Updated
2019-10-03
·
CVE-2018-5508
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP PEM versions 11.2.1, 11.5.1 through 11.5.5, 11.6.0 through 11.6.2, 12.0.0 through 12.1.3.1, 13.0.0
Description
The issue occurs when TMM processes compressed data through a Virtual Server with an associated PEM profile that uses the content insertion option, potentially causing TMM to crash under certain conditions.
Recommendations
For versions 11.2.1, consider disabling the content insertion option in the PEM profile until a fix is available.
For versions 11.5.1 through 11.5.5, restrict the use of the Virtual Server with the associated PEM profile.
For versions 11.6.0 through 11.6.2, avoid using the content insertion option in the PEM profile.
For versions 12.0.0 through 12.1.3.1, disable the processing of compressed data through the Virtual Server with the associated PEM profile.
For version 13.0.0, consider temporarily removing the PEM profile from the Virtual Server.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F5 Big-Ip Pem