CVE-2019-10153

MEDIUM

fence-agents < 4.3.4 - Denial of Service via Non-ASCII Character Handling

Title source: llm
STIX 2.1

Description

A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.

References (4)

Core 4
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10153
Patch, Third Party Advisory x_refsource_confirm
https://github.com/ClusterLabs/fence-agents/pull/255
Patch, Third Party Advisory x_refsource_confirm
https://github.com/ClusterLabs/fence-agents/pull/272
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2037

Scores

CVSS v3 5.0
EPSS 0.0034
EPSS Percentile 57.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

Details

CWE
CWE-172
Status published
Products (4)
clusterlabs/fence-agents < 4.3.4
redhat/enterprise_linux 8.0
redhat/enterprise_linux_server 7.0
redhat/enterprise_linux_workstation 7.0
Published Jul 30, 2019
Tracked Since Feb 18, 2026