F5 Networks BIG-IP : TMM vulnerability (K52167636)
Medium Nessus Plugin ID 118675
SynopsisThe remote device is missing a vendor-supplied security patch.
DescriptionFeatures in the BIG-IP system that utilizeinflate functionality directly, via an iRule, or via the inflate code from PEM module are subjected to a service disruption via a 'Zip Bomb' attack.(CVE-2017-6153)
BIG-IP systems deployed in Forward Proxy mode with the inflate functionality enabled are at greatest risk for this vulnerability.
BIG-IP systems that are collecting and manually decompressing data by way of iRules (using HTTP::collect and DECOMPRESS/COMPRESS ) have additional risk, as this situation may increase the likelihood of successful exploitation. The control plane is not impacted by this issue; this issue isobserved on the data plane.
SolutionUpgrade to one of the non-vulnerable versions listed in the F5 Solution K52167636.