Summary
A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe 11.16.2. See the Symptoms section for more details.
- If you DO NOT distribute lmadmin to your customers, there is no further action on your part.
- If you DO distribute lmadmin to your customers, you must distribute to those same customers the security update mentioned in the Resolution section of this article.
This security vulnerability has been assigned the CVE ID number of CVE-2019-8960.
Symptoms
The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a particular flag set in the original message, but no second message received, the function eventually returns an unexpected value which leads to an exception being thrown. The end result can be process termination.
Resolution
FlexNet Publisher 2019 R3 SP1 (11.16.5.1) addresses the security vulnerability and is available from the Flexera/Revenera Product and License Center (login required).
We advise all FlexNet Publisher customers update lmadmin.exe to FlexNet Publisher 11.16.5.1.
Related Articles
CVE-2019-8962 remediated in FlexNet Publisher 5Number of Views CVE-2018-20032 Remediated in FlexNet Publisher 6Number of Views CVE-2020-12081 Remediated in FlexNet Publisher 4Number of Views CVE-2018-20034 remediated in FlexNet Publisher 7Number of Views CVE-2018-20033 Remediated in FlexNet Publisher 7Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago