Vulnerability Description
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Horizon Daas | >= 8.0.0, < 9.0.0.0 |
| Vmware | Esxi | 6.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux For Ibm Z Systems | 6.0_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 7.7_s390x |
| Redhat | Enterprise Linux For Power Big Endian | 6.0_ppc64 |
| Redhat | Enterprise Linux For Power Big Endian Eus | 7.7_ppc64 |
| Redhat | Enterprise Linux For Power Little Endian | 7.0_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian Eus | 7.7_ppc64le |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server Aus | 7.7 |
| Redhat | Enterprise Linux Server Eus | 7.7 |
| Redhat | Enterprise Linux Server Tus | 7.7 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Openslp | Openslp | <= 2.0.0 |
| Fedoraproject | Fedora | 30 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2019/12/10/2Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/12/11/2Mailing ListThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2019-0022.htmlPatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:4240Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0199Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproRelease Notes
- https://security.gentoo.org/glsa/202005-12Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/12/10/2Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/12/11/2Mailing ListThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2019-0022.htmlPatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:4240Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0199Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproRelease Notes
FAQ
What is CVE-2019-5544?
CVE-2019-5544 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base scor...
How severe is CVE-2019-5544?
CVE-2019-5544 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-5544?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Horizon Daas, Vmware Esxi, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux For Ibm Z Systems, Redhat Enterprise Linux For Ibm Z Systems Eus.