Operational Defect Database

BugZero found this defect 445 days ago.

F5 | 1238897

TMM TCL interpreter's non-TMM "compat" memcasechr broken in 64-bit build

Last update date:

4/26/2024

Affected products:

BIG-IP

BIG-IP All

Affected releases:

11.0.0

11.6.0 HF1

11.6.0 HF2

11.6.0 HF3

11.6.0 HF4

11.6.0 HF5

11.6.0 HF6

11.6.0 HF7

11.6.0 HF8

11.5.1 HF1

11.6.1 HF1

11.5.1 HF2

Fixed releases:

No fixed releases provided.

Description:

Severity: 4-Minor ... Symptoms ... The TMM's base TCL interpreter (tmm_tcl) is used both in TMM and in non-TMM environments like APMD. ... The TMM has it's own implementation of memcasechr which is preferred to the "compat" implementation in the TCL interpreter itself as TMM statically links tmm_tcl while non-TMM usage is dynamically linked. ... Impact ... The memcasechr is broken in 64-bit build. ... Following VPE rule does not work (option -nocase): expr {[string first -nocase "bid" [mcget {session.oauth.scope.last.jwt.scope}]] >= 0} ... Conditions

Additional Resources / Links

Share:

BugZero® Risk Score

What's this?

Coming soon

Status

New

Learn More

Search:

...