Vulnerability CVE-2018-20164


Published: 2019-02-13

Description:
An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression Denial of Service (ReDoS) issue allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to a value containing a long digit string. (The UAP-Core project contains the vulnerability, propagating to all implementations.)

See advisories in our WLB2 database:
Topic
Author
Date
Med.
UA-Parser Denial Of Service
Luc Gommans
12.01.2019

Type:

CWE-185

(Incorrect Regular Expression)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
https://github.com/ua-parser/uap-core/commit/010ccdc7303546cd22b9da687c29f4a996990014
https://github.com/ua-parser/uap-core/commit/156f7e12b215bddbaf3df4514c399d683e6cdadc
https://github.com/ua-parser/uap-core/issues/332
https://www.x41-dsec.de/lab/advisories/x41-2018-009-uaparser/

Copyright 2024, cxsecurity.com

 

Back to Top