Splunk 4.3.x Denial Of Service

2012.11.03
Credit: nruns
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-399


CVSS Base Score: 5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: None
Integrity impact: None
Availability impact: Partial

n.runs AG http://www.nruns.com/ security(at)nruns.com n.runs-SA-2012.003 02-Nov-2012 ________________________________________________________________________ Vendors: Splunk Inc., http://www.splunk.com Product: Splunk 4.3.x (+ possibly earlier versions) Vulnerability: Unauth. remote denial of service against splunkweb Tracking IDs: CVE-2012-1150 SPL-53249 ___________________________________________________________________________ Vendor communication: 2012/09/03 Reported the issue via Splunk's website 2012/09/04 Splunk responds and assigns tracking ID, plans fix for 5.0. Replacing the Python version in a maintenance release (4.3.x) was considered too risky. 2012/10/25 Splunk informs us that 5.0 will be available on November 1st. 2012/10/29 Splunk 5.0 is released. ___________________________________________________________________________ Overview: Splunkweb uses Python 2.7.2, which suffers from a vulnerability which allows an attacker to produce hash collisions for the hash table string hashing function. This leads to an O(n^2) complexity when inserting n keys (see http://bugs.python.org/issue13703). Description: An attacker can abuse this vulnerability by sending a POST request to Splunkweb (for example to the login form endpoint) with colliding keys. Even a moderate amount of POST data leads to a 100% CPU usage for the splunkweb process. Impact: Denial of service (CPU exhaustion) against the Splunk server. Fixes: This issue has been fixed in Splunk 5.0 by updating the Python version to 2.7.3 and enabling hash randomization. ________________________________________________________________________ Credits: Alexander Klink, n.runs AG (discovery) ________________________________________________________________________ References: This advisory and upcoming advisories: http://www.nruns.com/security_advisory.php ________________________________________________________________________ About n.runs: n.runs AG is a vendor-independent consulting company specialising in the areas of: IT Infrastructure, IT Security and IT Business Consulting. Copyright Notice: Unaltered electronic reproduction of this advisory is permitted. For all other reproduction or publication, in printing or otherwise, contact security@nruns.com for permission. Use of the advisory constitutes acceptance for use in an as is condition. All warranties are excluded. In no event shall n.runs be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if n.runs has been advised of the possibility of such damages. Copyright 2012 n.runs AG. All rights reserved. Terms of use apply.

References:

http://bugs.python.org/issue13703


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top