In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may not be properly cleaned up, potentially leading to resource starvation. Connections may be left in the connection table which then can only be removed by restarting TMM. Over time this may lead to the BIG-IP being unable to process further connections.
References
Link | Resource |
---|---|
https://support.f5.com/csp/article/K30201296 | Vendor Advisory |
http://www.securitytracker.com/id/1039674 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/101612 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Information
Published : 2017-10-27 07:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-0303
Mitre link : CVE-2017-0303
JSON object : View
CWE
CWE-459
Incomplete Cleanup
Products Affected
f5
- big-ip_link_controller
- big-ip_advanced_firewall_manager
- big-ip_websafe
- big-ip_application_security_manager
- big-ip_access_policy_manager
- big-ip_local_traffic_manager
- big-ip_application_acceleration_manager
- big-ip_policy_enforcement_manager