CVE-2017-0303 - Incomplete Cleanup

Severity

50%

Complexity

99%

Confidentiality

48%

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may not be properly cleaned up, potentially leading to resource starvation. Connections may be left in the connection table which then can only be removed by restarting TMM. Over time this may lead to the BIG-IP being unable to process further connections.

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may not be properly cleaned up, potentially leading to resource starvation. Connections may be left in the connection table which then can only be removed by restarting TMM. Over time this may lead to the BIG-IP being unable to process further connections.

CVSS 3.0 Base Score 7.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS 2.0 Base Score 5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).

Demo Examples

Incomplete Cleanup

CWE-459

Stream resources in a Java application should be released in a finally block, otherwise an exception thrown before the call to close() would result in an unreleased I/O resource. In the example below, the close() method is called in the try block (incorrect).


               
}
is.close();
log.error("Something bad happened: " + t.getMessage());

Overview

Type

F5

First reported 7 years ago

2017-10-27 14:29:00

Last updated 5 years ago

2019-10-03 00:03:00

Affected Software

F5 BIG-IP Local Traffic Manager 11.5.0

11.5.0

F5 Networks BIGIP Local Traffic Manager (LTM) 11.5.1

11.5.1

F5 BIG-IP Local Traffic Manager 11.5.2

11.5.2

F5 BIG-IP Local Traffic Manager 11.5.3

11.5.3

F5 Big-IP Local Traffic Manager 11.5.4

11.5.4

F5 Networks BIG-IP Local Traffic Manager 11.5.5

11.5.5

F5 BIG-IP Local Traffic Manager 11.6.0

11.6.0

F5 Networks BIG-IP Local Traffic Manager 11.6.1

11.6.1

F5 BIG-IP Local Traffic Manager (LTM) 12.0.0

12.0.0

F5 BIG-IP Local Traffic Manager (LTM) 12.1.0

12.1.0

F5 BIG-IP Local Traffic Manager (LTM) 12.1.1

12.1.1

F5 Big-IP Local Traffic Manager (LTM) 12.1.2

12.1.2

F5 Big-IP Local Traffic Manager (LTM) 13.0.0

13.0.0

F5 BIG-IP Application Acceleration Manager 11.5.0

11.5.0

F5 Networks BIGIP Application Acceleration Manager 11.5.1

11.5.1

F5 BIG-IP Application Acceleration Manager 11.5.2

11.5.2

F5 BIG-IP Application Acceleration Manager 11.5.3

11.5.3

F5 Big-IP Application Acceleration Manager 11.5.4

11.5.4

F5 Networks BIG-IP Application Acceleration Manager 11.5.5

11.5.5

F5 BIG-IP Application Acceleration Manager 11.6.0

11.6.0

F5 Networks BIG-IP Application Acceleration Manager 11.6.1

11.6.1

F5 BIG-IP Application Acceleration Manager (AAM) 12.0.0

12.0.0

F5 Networks BIG-IP Application Acceleration Manager 12.1.0

12.1.0

F5 BIG-IP Application Acceleration Manager (AAM) 12.1.1

12.1.1

F5 Big-IP Application Acceleration Manager (AAM) 12.1.2

12.1.2

F5 Big-IP Application Acceleration Manager (AAM) 13.0.0

13.0.0

F5 BIG-IP Advanced Firewall Manager 11.5.0

11.5.0

F5 Networks BIGIP Advanced Firewall Manager 11.5.1

11.5.1

F5 BIG-IP Advanced Firewall Manager 11.5.2

11.5.2

F5 BIG-IP Advanced Firewall Manager 11.5.3

11.5.3

F5 Big-IP Advanced Firewall Manager 11.5.4

11.5.4

F5 Networks BIG-IP Advanced Firewall Manager 11.5.5

11.5.5

F5 BIG-IP Advanced Firewall Manager 11.6.0

11.6.0

F5 Networks BIG-IP Advanced Firewall Manager 11.6.1

11.6.1

F5 BIG-IP Advanced Firewall Manager (APM) 12.0.0

12.0.0

F5 BIG-IP Advanced Firewall Manager (AFM) 12.1.0

12.1.0

F5 BIG-IP Advanced Firewall Manager (AFM) 12.1.1

12.1.1

F5 Big-IP Advanced Firewall Manager (AFM) 12.1.2

12.1.2

F5 Big-IP Advanced Firewall Manager (AFM) 13.0.0

13.0.0

F5 BIG-IP Access Policy Manager 11.5.0

11.5.0

F5 Big-IP Access Policy Manager (APM) 11.5.1

11.5.1

F5 BIG-IP Access Policy Manager 11.5.2

11.5.2

F5 BIG-IP Access Policy Manager 11.5.3

11.5.3

F5 Big-IP Access Policy Manager (APM) 11.5.4

11.5.4

F5 Networks BIG-IP Access Policy Manager 11.5.5

11.5.5

F5 Big-IP Access Policy Manager (APM) 11.6.0

11.6.0

F5 Networks BIG-IP Access Policy Manager 11.6.1

11.6.1

F5 BIG-IP Access Policy Manager (APM) 12.0.0

12.0.0

F5 BIG-IP Access Policy Manager (APM) 12.1.0

12.1.0

F5 BIG-IP Access Policy Manager (APM) 12.1.1

12.1.1

F5 Big-IP Access Policy Manager (APM) 12.1.2

12.1.2

F5 Big-IP Access Policy Manager (APM) 13.0.0

13.0.0

F5 BIG-IP Application Security Manager 11.5.0

11.5.0

F5 Networks BIG-IP Application Security Manager 11.5.1

11.5.1

F5 BIG-IP Application Security Manager 11.5.2

11.5.2

F5 BIG-IP Application Security Manager 11.5.3

11.5.3

F5 Big-IP Application Security Manager 11.5.4

11.5.4

F5 Networks BIG-IP Application Security Manager 11.5.5

11.5.5

F5 BIG-IP Application Security Manager 11.6.0

11.6.0

F5 Networks BIG-IP Application Security Manager 11.6.1

11.6.1

F5 BIG-IP Application Security Manager (ASM) 12.0.0

12.0.0

F5 BIG-IP Application Security Manager (ASM) 12.1.0

12.1.0

F5 BIG-IP Application Security Manager (ASM) 12.1.1

12.1.1

F5 Big-IP Application Security Manager (ASM) 12.1.2

12.1.2

F5 Big-IP Application Security Manager (ASM) 13.0.0

13.0.0

F5 BIG-IP Link Controller 11.5.0

11.5.0

F5 Networks BIGIP Link Controller 11.5.1

11.5.1

F5 BIG-IP Link Controller 11.5.2

11.5.2

F5 BIG-IP Link Controller 11.5.3

11.5.3

F5 Big-IP Link Controller 11.5.4

11.5.4

F5 Networks BIG-IP Link Controller 11.5.5

11.5.5

F5 BIG-IP Link Controller 11.6.0

11.6.0

F5 Networks BIG-IP Link Controller 11.6.1

11.6.1

F5 BIG-IP Link Controller 12.0.0

12.0.0

F5 BIG-IP Link Controller 12.1.0

12.1.0

F5 BIG-IP Link Controller 12.1.1

12.1.1

F5 Big-IP Link Controller 12.1.2

12.1.2

F5 Big-IP Link Controller 13.0.0

13.0.0

F5 BIG-IP Policy Enforcement Manager 11.5.0

11.5.0

F5 Networks BIGIP Policy Enforcement Manager 11.5.1

11.5.1

F5 BIG-IP Policy Enforcement Manager 11.5.2

11.5.2

F5 Networks BIG-IP Policy Enforcement Manager 11.5.3

11.5.3

F5 Big-IP Policy Enforcement Manager 11.5.4

11.5.4

F5 Networks BIG-IP Policy Enforcement Manager 11.5.5

11.5.5

F5 BIG-IP Policy Enforcement Manager 11.6.0

11.6.0

F5 Networks BIG-IP Policy Enforcement Manager 11.6.1

11.6.1

F5 BIG-IP Policy Enforcement Manager (PEM) 12.0.0

12.0.0

F5 BIG-IP Policy Enforcement Manager (PEM) 12.1.0

12.1.0

F5 BIG-IP Policy Enforcement Manager (PEM) 12.1.1

12.1.1

F5 Big-IP Policy Enforcement Manager (PEM) 12.1.2

12.1.2

F5 Big-IP Policy Enforcement Manager (PEM) 13.0.0

13.0.0

F5 Networks BIG-IP Websafe 1.0.0

1.0.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.