You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 

1374 lines
133 KiB

<!DOCTYPE html>
<html style="" class=" supports cssanimations flexbox csstransforms csstransforms3d" search-autocomplete="" lang="en"><head class="at-element-marker">
<meta http-equiv="content-type" content="text/html; charset=UTF-8"><style>body {transition: opacity ease-in 0.2s; }
body[unresolved] {opacity: 0; display: block; overflow: hidden; position: relative; }
</style>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<!--[if IEMobile]><meta http-equiv="cleartype" content="on"><![endif]-->
<!-- metaInclude -->
<meta name="avalon-host-info" content="kcs05.web.prod.ext.phx2.redhat.com">
<meta name="avalon-version" content="8ceb3fdb">
<meta name="cp-chrome-build-date" content="2021-01-11T21:25:27.957Z">
<meta name="viewport" content="width=device-width, initial-scale=1">
<!-- Chrome, Firefox OS and Opera -->
<meta name="theme-color" content="#000000">
<!-- Windows Phone -->
<meta name="msapplication-navbutton-color" content="#000000">
<!-- iOS Safari -->
<meta name="apple-mobile-web-app-status-bar-style" content="#000000">
<link rel="manifest" href="https://access.redhat.com/webassets/avalon/j/manifest.json">
<!-- Open Search - Tap to search -->
<link rel="search" type="application/opensearchdescription+xml" title="Red Hat Customer Portal" href="https://access.redhat.com/webassets/avalon/j/opensearch.xml">
<!-- title -->
<title>CVE-2019-14899- Red Hat Customer Portal</title>
<!-- /title -->
<script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/nr-768.js"></script><script type="text/javascript">
window.portal = {
analytics : {},
host : "https://access.redhat.com",
idp_url : "https://sso.redhat.com",
lang : "en",
version : "8ceb3fdb",
builddate : "2021-01-11T21:25:27.957Z",
fetchdate : "2021-01-12T08:26:57-0500",
nrid : "14615289",
nrlk : "2a497fa56f"
};
</script>
<script type="text/javascript">
if (!/\/logout.*/.test(location.pathname) && portal.host === location.origin && document.cookie.indexOf('rh_sso_session') >= 0 && !(document.cookie.indexOf('rh_jwt') >= 0)) window.location = '/login?redirectTo=' + encodeURIComponent(window.location.href);
</script>
<!-- cssInclude -->
<link rel="shortcut icon" href="https://access.redhat.com/webassets/avalon/g/favicon.ico">
<link media="all" rel="stylesheet" type="text/css" href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/bootstrap.css">
<link media="all" rel="stylesheet" type="text/css" href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/bootstrap-grid.css">
<link media="all" rel="stylesheet" type="text/css" href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/main.css">
<link media="all" rel="stylesheet" type="text/css" href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/components.css">
<link media="all" rel="stylesheet" type="text/css" href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pages.css">
<link href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/chosen.css" rel="stylesheet" type="text/css">
<!--[if lte IE 9]>
<link media="all" rel="stylesheet" type="text/css" href="https://access.redhat.com/chrome_themes/nimbus/css/ie.css" />
<![endif]-->
<noscript>
<style type="text/css" media="screen"> .primary-nav { display: block; } </style>
</noscript>
<link rel="preload" href="https://static.redhat.com/libs/redhat/redhat-font/2/webfonts/RedHatText/RedHatText-Regular.woff" as="font" type="font/woff" crossorigin="">
<link rel="preload" href="https://static.redhat.com/libs/redhat/redhat-font/2/webfonts/RedHatText/RedHatText-Medium.woff" as="font" type="font/woff" crossorigin="">
<link rel="preload" href="https://static.redhat.com/libs/redhat/redhat-font/2/webfonts/RedHatDisplay/RedHatDisplay-Regular.woff" as="font" type="font/woff" crossorigin="">
<link rel="preload" href="https://static.redhat.com/libs/redhat/redhat-font/2/webfonts/RedHatDisplay/RedHatDisplay-Medium.woff" as="font" type="font/woff" crossorigin="">
<link rel="preload" href="https://static.redhat.com/libs/redhat/redhat-font/2/webfonts/RedHatDisplay/RedHatDisplay-Bold.woff" as="font" type="font/woff" crossorigin="">
<!-- /cssInclude -->
<script type="text/javascript" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/require.js" data-main="/webassets/avalon/j/"></script>
<!-- HTML5 Shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js"></script>
<script src="https://oss.maxcdn.com/respond/1.4.2/respond.min.js"></script>
<script src="https://access.redhat.com/chrome_themes/nimbus/js/ie8.js"></script>
<![endif]-->
<!-- TrustArc -->
<script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/trustarc.js"></script><script type="text/javascript" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/notice" id="truste_0.2776822435952252"></script>
<title>cve-details</title>
<link href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/app.css" rel="preload" as="style"><link href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/app.js" rel="preload" as="script"><link href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/chunk-vendors.js" rel="preload" as="script"><link href="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/app.css" rel="stylesheet"><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="https://access.redhat.com/webassets/avalon/j/lib/require-css/require.css.min.js" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/require_002.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="rhn-modal" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/rhn-modal.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="status-widget" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/status-widget.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="avatars" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/avatars.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="wc" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/wc.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="pfe" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pfe.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="moment" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/moment.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="data-action" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/data-action.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="datatables.net" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/jquery.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="https://cdnjs.cloudflare.com/ajax/libs/webcomponentsjs/2.4.3/custom-elements-es5-adapter.js" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/custom-elements-es5-adapter.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="https://cdnjs.cloudflare.com/ajax/libs/webcomponentsjs/2.4.3/webcomponents-bundle.js" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/webcomponents-bundle.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="nimbus/tour" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/tour.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="datetime-moment" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/datetime-moment.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="introjs" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/introjs.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="ieSVGfix" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/ieSVGfix.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="public_modules/@cpelements/cp-search-autocomplete/dist/cp-search-autocomplete.umd" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/cp-search-autocomplete.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="public_modules/@patternfly/pfe-tabs/dist/pfe-tabs.umd.min" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pfe-tabs.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="public_modules/@patternfly/pfe-datetime/dist/pfe-datetime.umd.min" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pfe-datetime.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="public_modules/@patternfly/pfe-accordion/dist/pfe-accordion.umd.min" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pfe-accordion.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="public_modules/@patternfly/pfe-markdown/dist/pfe-markdown.umd.min" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pfe-markdown.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="public_modules/@patternfly/pfe-progress-indicator/dist/pfe-progress-indicator.umd.min" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pfe-progress-indicator.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="public_modules/@patternfly/pfelement/dist/pfelement.umd" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pfelement.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="public_modules/@patternfly/pfe-autocomplete/dist/pfe-autocomplete.umd" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/pfe-autocomplete.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="dtm" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/dtm.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="drupal-admin-drawer" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/drupal-admin-drawer.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="handlebars.runtime" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/handlebars.js"></script><script type="text/javascript" charset="utf-8" async="" data-requirecontext="_" data-requiremodule="drupal-admin-drawer-templates" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/templates.js"></script><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/AppMeasurement.js" async=""></script><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/AppMeasurement_Module_ActivityMap.js" async=""></script><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/AppMeasurement_Module_AudienceManagement.js" async=""></script><script id="mktgJS" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/rh.js"></script><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/RC0c7c8f7327404877982220697c38561e-source.js" async=""></script><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/RCe24729c2aa0c4497b46ebde0391a571e-source.js" async=""></script><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/RC26501910542e419888b714ed94470c80-source.js" async=""></script><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/RCacb097cce26f41e58941a22726815ef6-source.js" async=""></script><script>
console.log('You have qualified for CP003 - ALL - Sitewide - Search Auto Complete Test [PUSH]: B - Auto Complete');
document.querySelector("html").setAttribute("search-autocomplete", "");
</script></head>
<body class="en loggedOut" data-new-gr-c-s-check-loaded="8.869.0" data-gr-ext-installed="">
<div id="page-wrap" class="page-wrap">
<div id="pers-top-page-wrap" class="top-page-wrap pers-loader-bg">
<!--googleoff: all-->
<header class="masthead" id="masthead">
<script>
chrometwo_require(["wc"], function(wc){
wc.include("@cpelements/cp-search-autocomplete/dist/cp-search-autocomplete.umd");
});
</script>
<!-- Accessibility Nav & Header -->
<div class="accessibility-nav sr-only">
<a href="https://access.redhat.com/">
<h1>Red Hat <span>Customer </span><span>Portal</span></h1>
</a>
<p><a href="#cp-main">Skip to main content</a></p>
<nav aria-labelledby="accessibility-nav-heading">
<h2 id="accessibility-nav-heading">Main Navigation</h2>
<ul>
<li>
<a href="#" class="has-subnav"><span>Products &amp; Services</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/products">View All Products</a></li>
<li>
<a href="#" class="has-subnav"><span>Infrastructure and Management</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/products/red-hat-enterprise-linux/">Red Hat Enterprise Linux</a></li>
<li><a href="https://access.redhat.com/products/red-hat-virtualization/">Red Hat Virtualization</a></li>
<li><a href="https://access.redhat.com/products/identity-management/">Red Hat Identity Management</a></li>
<li><a href="https://access.redhat.com/products/red-hat-directory-server/">Red Hat Directory Server</a></li>
<li><a href="https://access.redhat.com/products/red-hat-certificate-system/">Red Hat Certificate System</a></li>
<li><a href="https://access.redhat.com/products/red-hat-satellite/">Red Hat Satellite</a></li>
<li><a href="https://access.redhat.com/products/red-hat-subscription-management/">Red Hat Subscription Management</a></li>
<li><a href="https://access.redhat.com/products/red-hat-update-infrastructure/">Red Hat Update Infrastructure</a></li>
<li><a href="https://access.redhat.com/insights/info/?intcmp=mm|p|im|rhaijan2016&amp;">Red Hat Insights</a></li>
<li><a href="https://access.redhat.com/products/red-hat-ansible-automation-platform/">Red Hat Ansible Automation Platform</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Cloud Computing</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/products/red-hat-cloudforms/">Red Hat CloudForms</a></li>
<li><a href="https://access.redhat.com/products/red-hat-openstack-platform/">Red Hat OpenStack Platform</a></li>
<li><a href="https://access.redhat.com/products/red-hat-openshift-container-platform/">Red Hat OpenShift Container Platform</a></li>
<li><a href="https://access.redhat.com/products/openshift-online-red-hat/">Red Hat OpenShift Online</a></li>
<li><a href="https://access.redhat.com/products/openshift-dedicated-red-hat/">Red Hat OpenShift Dedicated</a></li>
<li><a href="https://access.redhat.com/products/red-hat-advanced-cluster-management-for-kubernetes/">Red Hat Advanced Cluster Management for Kubernetes</a></li>
<li><a href="https://access.redhat.com/products/red-hat-quay/">Red Hat Quay</a></li>
<li><a href="https://access.redhat.com/products/red-hat-codeready-workspaces/">Red Hat CodeReady Workspaces</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Storage</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/products/red-hat-storage/">Red Hat Gluster Storage</a></li>
<li><a href="https://access.redhat.com/products/red-hat-hyperconverged-infrastructure/">Red Hat Hyperconverged Infrastructure</a></li>
<li><a href="https://access.redhat.com/products/red-hat-ceph-storage/">Red Hat Ceph Storage</a></li>
<li><a href="https://access.redhat.com/products/red-hat-openshift-container-storage">Red Hat Openshift Container Storage</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Runtimes</span></a>
<ul class="mm-hide">
<li aria-hidden="true">
<a href="#" class="back">Back</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-runtimes/">Red Hat Runtimes</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-enterprise-application-platform/">Red Hat JBoss Enterprise Application Platform</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-data-grid/">Red Hat Data Grid</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-web-server/">Red Hat JBoss Web Server</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-single-sign-on/">Red Hat Single Sign On</a>
</li>
<li>
<a href="https://access.redhat.com/products/spring-boot/">Red Hat support for Spring Boot</a>
</li>
<li>
<a href="https://access.redhat.com/products/nodejs/">Red Hat build of Node.js</a>
</li>
<li>
<a href="https://access.redhat.com/products/thorntail/">Red Hat build of Thorntail</a>
</li>
<li>
<a href="https://access.redhat.com/products/eclipse-vertx/">Red Hat build of Eclipse Vert.x</a>
</li>
<li>
<a href="https://access.redhat.com/products/openjdk/">Red Hat build of OpenJDK</a>
</li>
<li>
<a href="https://access.redhat.com/products/quarkus/">Red Hat build of Quarkus</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-codeready-studio/">Red Hat CodeReady Studio</a>
</li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Integration and Automation</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li>
<a href="https://access.redhat.com/products/red-hat-integration/">Red Hat Integration</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-fuse/">Red Hat Fuse</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-amq/">Red Hat AMQ</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-3scale/">Red Hat 3scale API Management</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-data-virtualization/">Red Hat JBoss Data Virtualization</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-process-automation/">Red Hat Process Automation</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-process-automation-manager/">Red Hat Process Automation Manager</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-decision-manager/">Red Hat Decision Manager</a>
</li>
</ul>
</li>
<li class="heading"><a class="cta-link cta-link-darkbg" href="https://access.redhat.com/support/">Support</a></li>
<li><a href="https://access.redhat.com/support/offerings/production/">Production Support</a></li>
<li><a href="https://access.redhat.com/support/offerings/developer/">Development Support</a></li>
<li><a href="https://access.redhat.com/product-life-cycles/">Product Life Cycles</a></li>
<li class="heading"><a class="cta-link cta-link-darkbg" href="https://access.redhat.com/documentation/">Documentation</a></li>
<li><a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux">Red Hat Enterprise Linux</a></li>
<li><a href="https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform">Red Hat JBoss Enterprise Application Platform</a></li>
<li><a href="https://access.redhat.com/documentation/en-us/red_hat_openstack_platform">Red Hat OpenStack Platform</a></li>
<li><a href="https://access.redhat.com/documentation/en-us/openshift_container_platform">Red Hat OpenShift Container Platform</a></li>
<li class="heading">Services</li>
<li><a href="https://www.redhat.com/en/services/consulting">Consulting</a></li>
<li><a href="https://access.redhat.com/support/offerings/tam/">Technical Account Management</a></li>
<li><a href="https://www.redhat.com/en/services/training-and-certification">Training &amp; Certifications</a></li>
<li class="heading"><a class="cta-link cta-link-darkbg" href="https://catalog.redhat.com/">Ecosystem Catalog</a></li>
<li><a href="https://access.redhat.com/ecosystem/partner-resources">Partner Resources</a></li>
<li><a href="https://access.redhat.com/public-cloud">Red Hat in the Public Cloud</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Tools</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/insights/info/?intcmp=mm|t|c1|rhaidec2015&amp;">Red Hat Insights</a></li>
<li class="heading">Tools</li>
<li><a href="https://access.redhat.com/solution-engine">Solution Engine</a></li>
<li><a href="https://access.redhat.com/downloads/content/package-browser">Packages</a></li>
<li><a href="https://access.redhat.com/errata/">Errata</a></li>
<li class="heading">Customer Portal Labs</li>
<li><a href="https://access.redhat.com/labs/">Explore Labs</a></li>
<li><a href="https://access.redhat.com/labs/#?type=config">Configuration</a></li>
<li><a href="https://access.redhat.com/labs/#?type=deploy">Deployment</a></li>
<li><a href="https://access.redhat.com/labs/#?type=security">Security</a></li>
<li><a href="https://access.redhat.com/labs/#?type=troubleshoot">Troubleshooting</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Security</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/security/">Product Security Center</a></li>
<li class="heading">Security Updates</li>
<li><a href="https://access.redhat.com/security/security-updates/#/security-advisories">Security Advisories</a></li>
<li><a href="https://access.redhat.com/security/security-updates/#/cve">Red Hat CVE Database</a></li>
<li><a href="https://access.redhat.com/security/security-updates/#/security-labs">Security Labs</a></li>
<li class="heading">Resources</li>
<li><a href="https://access.redhat.com/security/overview/">Overview</a></li>
<li><a href="https://access.redhat.com/blogs/product-security">Security Blog</a></li>
<li><a href="https://www.redhat.com/security/data/metrics/">Security Measurement</a></li>
<li><a href="https://access.redhat.com/security/updates/classification/">Severity Ratings</a></li>
<li><a href="https://access.redhat.com/security/updates/backporting/">Backporting Policies</a></li>
<li><a href="https://access.redhat.com/security/team/key/">Product Signing (GPG) Keys</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Community</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li class="heading">Customer Portal Community</li>
<li><a href="https://access.redhat.com/discussions?keyword=&amp;name=&amp;product=All&amp;category=All&amp;tags=All">Discussions</a></li>
<li><a href="https://access.redhat.com/blogs/">Blogs</a></li>
<li><a href="https://access.redhat.com/groups/">Private Groups</a></li>
<li><a href="https://access.redhat.com/community/">Community Activity</a></li>
<li class="heading">Customer Events</li>
<li><a href="https://access.redhat.com/convergence/">Red Hat Convergence</a></li>
<li><a href="http://www.redhat.com/summit/">Red Hat Summit</a></li>
<li class="heading">Stories</li>
<li><a href="https://access.redhat.com/subscription-value/">Red Hat Subscription Value</a></li>
<li><a href="https://access.redhat.com/you-asked-we-acted/">You Asked. We Acted.</a></li>
<li><a href="http://www.redhat.com/en/open-source">Open Source Communities</a></li>
</ul>
</li>
<li><a href="https://access.redhat.com/management/">Subscriptions</a></li>
<li><a href="https://access.redhat.com/downloads/">Downloads</a></li>
<li><a href="https://catalog.redhat.com/software/containers/explore/">Containers</a></li>
<li><a href="https://access.redhat.com/support/cases/">Support Cases</a></li>
<li>
<a href="#" class="has-subnav"><span>Account</span></a>
<ul class="utility mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li class="mobile-accountLinksLoggedOut unauthenticated" style="display: block;"><a href="https://access.redhat.com/login?redirectTo=https%3A%2F%2Faccess.redhat.com%2Fsecurity%2Fcve%2FCVE-2019-14899" id="accessibility-accountLogin">Log In</a></li>
<li class="mobile-accountLinksLoggedOut unauthenticated" style="display: block;"><a href="https://www.redhat.com/wapps/ugc/register.html">Register</a></li>
<li class="mobile-accountLinksLoggedIn authenticated">
<div class="account-info" id="accessibility-accountUser">
<div class="account-name"><strong id="accessibility-userFullName"></strong></div>
<div class="account-org"><span id="accessibility-userOrg"></span></div>
<div class="account-number mobile-accountNumber"><span class="property">Red Hat Account Number:</span> <span class="value"></span></div>
</div>
</li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://www.redhat.com/wapps/ugc/protected/personalInfo.html">Account Details</a></li>
<!-- <li class="mobile-accountLinksLoggedIn authenticated"><a href="https://www.redhat.com/wapps/ugc/protected/prefs.html">Newsletter and Contact Preferences</a></li> -->
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://www.redhat.com/wapps/ugc/protected/usermgt/userList.html" class="user-management-link" hidden="hidden">User Management</a></li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://www.redhat.com/wapps/ugc/protected/account.html">Account Maintenance</a></li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://access.redhat.com/user">My Profile</a></li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://access.redhat.com/user" id="accessibility-userNotificationsLink">Notifications</a></li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://access.redhat.com/help/">Help</a></li>
<li class="logout mobile-accountLinksLoggedIn authenticated"><a href="https://sso.redhat.com/auth/realms/redhat-external/logout?redirectUrl=https%3A%2F%2Faccess.redhat.com%2Flogout">Log Out</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Language</span></a>
<ul class="utility mm-hide" id="accessibility-localesMenu">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=en&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" id="accessibility-en">English</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=ko&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" id="accessibility-ko">한국어</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=ja&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" id="accessibility-ja">日本語</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=zh_CN&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" id="accessibility-zh_CN">中文 (中国)</a></li>
</ul>
</li>
</ul>
</nav>
</div>
<!-- Mobile Header -->
<nav class="mobile-nav-bar hidden-sm hidden-md hidden-lg" aria-hidden="true">
<button id="menu-btn" class="menu menu-white" type="button" aria-label="Toggle Navigation">
<span class="lines"></span>
</button>
<a class="logo" href="https://access.redhat.com/">
<span class="logo-crop">
<!-- logo -->
<span class="sr-only">Red Hat Customer Portal</span>
<svg aria-hidden="true" class="rh-logo" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 950 200">
<defs>
<style>
.rh-logo-type {
fill:#fff;
}
.rh-logo-hat {
fill:#e00;
}
</style>
</defs>
<g id="Two_lines" data-name="Two lines"><g id="Two_line_logo" data-name="Two line logo"><path class="rh-logo-type" d="M318.62,9.25h25.44c11.13,0,18.64,6.72,18.64,16.56,0,7.36-4.47,13-11.51,15.36l12.48,24.08h-9.29l-11.6-23H327v23h-8.4Zm8.4,7.36V35.33h16.33c6.55,0,10.87-3.76,10.87-9.36s-4.32-9.36-10.87-9.36Z"></path><path class="rh-logo-type" d="M387.5,66a21,21,0,0,1-21.36-21.12c0-11.76,9-21,20.4-21,11.2,0,19.68,9.28,19.68,21.28v2.32H374.06a13.74,13.74,0,0,0,13.76,11.68,15.84,15.84,0,0,0,10.32-3.6l5.13,5A24.33,24.33,0,0,1,387.5,66ZM374.14,41.49H398.3c-1.19-6.24-6-10.88-11.92-10.88C380.22,30.61,375.34,35,374.14,41.49Z"></path><path class="rh-logo-type" d="M445.18,61.41a19.23,19.23,0,0,1-12.48,4.48c-11.52,0-20.56-9.2-20.56-21a20.72,20.72,0,0,1,33-17V9.25l8-1.76V65.25h-7.92Zm-11.36-2.48a14.67,14.67,0,0,0,11.28-4.88V35.57a14.89,14.89,0,0,0-11.28-4.8,13.63,13.63,0,0,0-13.84,14A13.77,13.77,0,0,0,433.82,58.93Z"></path><path class="rh-logo-type" d="M480.22,9.25h8.4v24h29.76v-24h8.4v56h-8.4V40.85H488.62v24.4h-8.4Z"></path><path class="rh-logo-type" d="M534.38,53.57c0-7.68,6.24-12.4,16.48-12.4A28.75,28.75,0,0,1,562,43.41V39.09c0-5.76-3.44-8.64-9.92-8.64-3.76,0-7.6,1-12.64,3.44l-3-6c6.08-2.88,11.36-4.16,16.72-4.16,10.56,0,16.64,5.2,16.64,14.56v27H562V61.73A19.32,19.32,0,0,1,549.34,66C540.46,66,534.38,60.93,534.38,53.57Zm16.8,6.48A15.66,15.66,0,0,0,562,56.21v-7a21.15,21.15,0,0,0-10.48-2.48c-5.84,0-9.44,2.64-9.44,6.72C542.06,57.33,545.74,60.05,551.18,60.05Z"></path><path class="rh-logo-type" d="M582.7,31.25h-8.64V24.53h8.64V14.13l7.92-1.92V24.53h12v6.72h-12V53.33c0,4.16,1.68,5.68,6,5.68a15.72,15.72,0,0,0,5.84-1v6.72a26.5,26.5,0,0,1-7.6,1.2c-7.92,0-12.16-3.76-12.16-10.8Z"></path><path class="rh-logo-type" d="M361,132.21l7.59,7.52a30.76,30.76,0,0,1-23,10.32c-16.88,0-29.84-12.56-29.84-28.8s13-28.88,29.84-28.88c9,0,18.09,4.08,23.28,10.48l-7.83,7.76a19.52,19.52,0,0,0-15.45-7.6c-10.16,0-17.92,7.84-17.92,18.24A17.8,17.8,0,0,0,346,139.33,19.24,19.24,0,0,0,361,132.21Z"></path><path class="rh-logo-type" d="M383.74,131.81c0,5.36,3.44,8.8,8.64,8.8a10.05,10.05,0,0,0,8.65-4.16V107.57h11v41.68H401v-3.36a17.79,17.79,0,0,1-11.77,4.16c-9.68,0-16.48-6.88-16.48-16.64V107.57h11Z"></path><path class="rh-logo-type" d="M422.46,137c4.88,3.2,9.12,4.72,13.52,4.72,4.88,0,8.08-1.76,8.08-4.4,0-2.16-1.6-3.36-5.2-3.92l-8-1.2c-8.24-1.28-12.64-5.36-12.64-12.08,0-8.08,6.72-13.2,17.36-13.2a30.75,30.75,0,0,1,17.12,5.2l-5.28,7c-4.56-2.72-8.64-4-12.88-4-4,0-6.56,1.6-6.56,4.08,0,2.24,1.6,3.36,5.68,3.92l8,1.2c8.16,1.2,12.72,5.44,12.72,11.92,0,7.84-7.76,13.76-18.24,13.76-7.6,0-14.4-2-19.12-5.76Z"></path><path class="rh-logo-type" d="M464.7,116.77h-8.56v-9.2h8.56V96.93l11-2.48v13.12H487.5v9.2H475.66v18.48c0,3.92,1.52,5.36,5.76,5.36a16.86,16.86,0,0,0,5.84-1v9a34,34,0,0,1-8.48,1.28c-9.28,0-14.08-4.24-14.08-12.4Z"></path><path class="rh-logo-type" d="M512.86,106.77c12.48,0,22.24,9.52,22.24,21.68s-9.76,21.6-22.24,21.6-22.24-9.44-22.24-21.6S500.38,106.77,512.86,106.77Zm11.52,21.68c0-6.88-5-12.16-11.52-12.16s-11.52,5.28-11.52,12.16c0,6.72,5,12.08,11.52,12.08S524.38,135.17,524.38,128.45Z"></path><path class="rh-logo-type" d="M541.82,107.57h11v3.12a16.21,16.21,0,0,1,10.88-3.92A15,15,0,0,1,576.22,113,17.16,17.16,0,0,1,590,106.77c9.36,0,15.91,6.8,15.91,16.56v25.92h-11V124.93c0-5.28-3-8.72-7.83-8.72a9.37,9.37,0,0,0-8,4.16,18.89,18.89,0,0,1,.23,3v25.92h-11V124.93c0-5.28-3-8.72-7.84-8.72a9.3,9.3,0,0,0-7.76,3.76v29.28h-11Z"></path><path class="rh-logo-type" d="M634.78,150.05c-12.64,0-22.4-9.44-22.4-21.6a21.28,21.28,0,0,1,21.44-21.6c11.84,0,20.64,9.6,20.64,22.4v2.88h-31a12,12,0,0,0,11.84,8.72,13.12,13.12,0,0,0,9.2-3.36l7.2,6.56A25,25,0,0,1,634.78,150.05Zm-11.44-25.76h20.4c-1.36-5-5.36-8.4-10.16-8.4C628.54,115.89,624.7,119.17,623.34,124.29Z"></path><path class="rh-logo-type" d="M661.18,107.57h11v4.56a13.26,13.26,0,0,1,11.12-5.52,9.44,9.44,0,0,1,4.56,1v9.6a14,14,0,0,0-5.6-1.12,11,11,0,0,0-10.08,6.24v27h-11Z"></path><path class="rh-logo-type" d="M710.54,93.25h28.08c11,0,18.8,7.28,18.8,17.6,0,10-7.92,17.28-18.8,17.28H722.14v21.12h-11.6Zm11.6,10v15.28h15.2c5,0,8.32-3,8.32-7.6s-3.28-7.68-8.32-7.68Z"></path><path class="rh-logo-type" d="M782.14,106.77c12.48,0,22.24,9.52,22.24,21.68s-9.76,21.6-22.24,21.6-22.24-9.44-22.24-21.6S769.66,106.77,782.14,106.77Zm11.52,21.68c0-6.88-5-12.16-11.52-12.16s-11.52,5.28-11.52,12.16c0,6.72,5,12.08,11.52,12.08S793.66,135.17,793.66,128.45Z"></path><path class="rh-logo-type" d="M811.1,107.57h11v4.56a13.26,13.26,0,0,1,11.12-5.52,9.44,9.44,0,0,1,4.56,1v9.6a14,14,0,0,0-5.6-1.12,11,11,0,0,0-10.08,6.24v27h-11Z"></path><path class="rh-logo-type" d="M850,116.77h-8.56v-9.2H850V96.93l11-2.48v13.12h11.84v9.2H860.94v18.48c0,3.92,1.52,5.36,5.76,5.36a16.86,16.86,0,0,0,5.84-1v9a34,34,0,0,1-8.48,1.28c-9.28,0-14.08-4.24-14.08-12.4Z"></path><path class="rh-logo-type" d="M876.22,137.17c0-7.92,6.4-12.64,17.12-12.64a33.71,33.71,0,0,1,10.16,1.6v-3c0-4.8-3-7.28-8.8-7.28-3.52,0-7.44,1.12-12.72,3.44l-4-8.08a43.46,43.46,0,0,1,18.56-4.48c11.28,0,17.76,5.6,17.76,15.44v27H903.5v-2.88a19.81,19.81,0,0,1-12.08,3.6C882.46,150,876.22,144.77,876.22,137.17Zm18.08,5a15.78,15.78,0,0,0,9.2-2.64v-6.24a24.22,24.22,0,0,0-8.8-1.52c-5,0-8,2-8,5.2S889.66,142.13,894.3,142.13Z"></path><path class="rh-logo-type" d="M933.58,149.25h-11v-56l11-2.4Z"></path><g id="Hat_icon" data-name="Hat icon"><path id="Red_hat" data-name="Red hat" class="rh-logo-hat" d="M129,92.24c12.5,0,30.61-2.58,30.61-17.46a14,14,0,0,0-.31-3.42L151.82,39c-1.72-7.12-3.23-10.35-15.74-16.6-9.7-5-30.82-13.15-37.07-13.15-5.83,0-7.55,7.54-14.45,7.54-6.68,0-11.64-5.6-17.89-5.6-6,0-9.92,4.1-12.93,12.5,0,0-8.41,23.72-9.49,27.16A6.43,6.43,0,0,0,44,52.79C44,62,80.32,92.24,129,92.24Zm32.55-11.42c1.72,8.19,1.72,9.05,1.72,10.13,0,14-15.73,21.77-36.43,21.77-46.77,0-87.73-27.37-87.73-45.48a18.32,18.32,0,0,1,1.51-7.33C23.77,60.77,2,63.79,2,83c0,31.48,74.59,70.28,133.65,70.28,45.27,0,56.7-20.48,56.7-36.65C192.35,103.88,181.35,89.44,161.52,80.82Z"></path><path class="rh-logo-band" id="Black_band" data-name="Black band" d="M161.52,80.82c1.72,8.19,1.72,9.05,1.72,10.13,0,14-15.73,21.77-36.43,21.77-46.77,0-87.73-27.37-87.73-45.48a18.32,18.32,0,0,1,1.51-7.33l3.66-9.06A6.43,6.43,0,0,0,44,52.79C44,62,80.32,92.24,129,92.24c12.5,0,30.61-2.58,30.61-17.46a14,14,0,0,0-.31-3.42Z"></path></g><path id="Dividing_line" data-name="Dividing line" class="rh-logo-type" d="M255.47,160.75a2.25,2.25,0,0,1-2.25-2.25V4.25a2.25,2.25,0,0,1,4.5,0V158.5A2.25,2.25,0,0,1,255.47,160.75Z"></path></g></g>
</svg>
</span>
</a>
<button class="btn btn-search btn-utility" data-target="#site-search">
<span class="web-icon-search"></span>
<span class="link-text">Search</span>
</button>
</nav>
<!-- Mobile Menu Drawer -->
<div class="nav-drawer-backdrop"></div><div class="nav-drawer mobile-nav-drawer hidden-sm hidden-md hidden-lg" aria-hidden="true">
<nav class="nav-container">
<ul>
<li>
<a href="#" class="has-subnav"><span>Products &amp; Services</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/products">View All Products</a></li>
<li>
<a href="#" class="has-subnav"><span>Infrastructure and Management</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/products/red-hat-enterprise-linux/">Red Hat Enterprise Linux</a></li>
<li><a href="https://access.redhat.com/products/red-hat-virtualization/">Red Hat Virtualization</a></li>
<li><a href="https://access.redhat.com/products/identity-management/">Red Hat Identity Management</a></li>
<li><a href="https://access.redhat.com/products/red-hat-directory-server/">Red Hat Directory Server</a></li>
<li><a href="https://access.redhat.com/products/red-hat-certificate-system/">Red Hat Certificate System</a></li>
<li><a href="https://access.redhat.com/products/red-hat-satellite/">Red Hat Satellite</a></li>
<li><a href="https://access.redhat.com/products/red-hat-subscription-management/">Red Hat Subscription Management</a></li>
<li><a href="https://access.redhat.com/products/red-hat-update-infrastructure/">Red Hat Update Infrastructure</a></li>
<li><a href="https://access.redhat.com/insights/info/?intcmp=mm|p|im|rhaijan2016&amp;">Red Hat Insights</a></li>
<li><a href="https://access.redhat.com/products/red-hat-ansible-automation-platform/">Red Hat Ansible Automation Platform</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Cloud Computing</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/products/red-hat-cloudforms/">Red Hat CloudForms</a></li>
<li><a href="https://access.redhat.com/products/red-hat-openstack-platform/">Red Hat OpenStack Platform</a></li>
<li><a href="https://access.redhat.com/products/red-hat-openshift-container-platform/">Red Hat OpenShift Container Platform</a></li>
<li><a href="https://access.redhat.com/products/openshift-online-red-hat/">Red Hat OpenShift Online</a></li>
<li><a href="https://access.redhat.com/products/openshift-dedicated-red-hat/">Red Hat OpenShift Dedicated</a></li>
<li><a href="https://access.redhat.com/products/red-hat-advanced-cluster-management-for-kubernetes/">Red Hat Advanced Cluster Management for Kubernetes</a></li>
<li><a href="https://access.redhat.com/products/red-hat-quay/">Red Hat Quay</a></li>
<li><a href="https://access.redhat.com/products/red-hat-codeready-workspaces/">Red Hat CodeReady Workspaces</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Storage</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/products/red-hat-storage/">Red Hat Gluster Storage</a></li>
<li><a href="https://access.redhat.com/products/red-hat-hyperconverged-infrastructure/">Red Hat Hyperconverged Infrastructure</a></li>
<li><a href="https://access.redhat.com/products/red-hat-ceph-storage/">Red Hat Ceph Storage</a></li>
<li><a href="https://access.redhat.com/products/red-hat-openshift-container-storage">Red Hat Openshift Container Storage</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Runtimes</span></a>
<ul class="mm-hide">
<li aria-hidden="true">
<a href="#" class="back">Back</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-runtimes/">Red Hat Runtimes</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-enterprise-application-platform/">Red Hat JBoss Enterprise Application Platform</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-data-grid/">Red Hat Data Grid</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-web-server/">Red Hat JBoss Web Server</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-single-sign-on/">Red Hat Single Sign On</a>
</li>
<li>
<a href="https://access.redhat.com/products/spring-boot/">Red Hat support for Spring Boot</a>
</li>
<li>
<a href="https://access.redhat.com/products/nodejs/">Red Hat build of Node.js</a>
</li>
<li>
<a href="https://access.redhat.com/products/thorntail/">Red Hat build of Thorntail</a>
</li>
<li>
<a href="https://access.redhat.com/products/eclipse-vertx/">Red Hat build of Eclipse Vert.x</a>
</li>
<li>
<a href="https://access.redhat.com/products/openjdk/">Red Hat build of OpenJDK</a>
</li>
<li>
<a href="https://access.redhat.com/products/quarkus/">Red Hat build of Quarkus</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-codeready-studio/">Red Hat CodeReady Studio</a>
</li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Integration and Automation</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li>
<a href="https://access.redhat.com/products/red-hat-integration/">Red Hat Integration</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-fuse/">Red Hat Fuse</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-amq/">Red Hat AMQ</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-3scale/">Red Hat 3scale API Management</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-data-virtualization/">Red Hat JBoss Data Virtualization</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-process-automation/">Red Hat Process Automation</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-process-automation-manager/">Red Hat Process Automation Manager</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-decision-manager/">Red Hat Decision Manager</a>
</li>
</ul>
</li>
<li class="heading"><a class="cta-link cta-link-darkbg" href="https://access.redhat.com/support/">Support</a></li>
<li><a href="https://access.redhat.com/support/offerings/production/">Production Support</a></li>
<li><a href="https://access.redhat.com/support/offerings/developer/">Development Support</a></li>
<li><a href="https://access.redhat.com/product-life-cycles/">Product Life Cycles</a></li>
<li class="heading"><a class="cta-link cta-link-darkbg" href="https://access.redhat.com/documentation/">Documentation</a></li>
<li><a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux">Red Hat Enterprise Linux</a></li>
<li><a href="https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform">Red Hat JBoss Enterprise Application Platform</a></li>
<li><a href="https://access.redhat.com/documentation/en-us/red_hat_openstack_platform">Red Hat OpenStack Platform</a></li>
<li><a href="https://access.redhat.com/documentation/en-us/openshift_container_platform">Red Hat OpenShift Container Platform</a></li>
<li class="heading">Services</li>
<li><a href="https://www.redhat.com/en/services/consulting">Consulting</a></li>
<li><a href="https://access.redhat.com/support/offerings/tam/">Technical Account Management</a></li>
<li><a href="https://www.redhat.com/en/services/training-and-certification">Training &amp; Certifications</a></li>
<li class="heading"><a class="cta-link cta-link-darkbg" href="https://catalog.redhat.com/">Ecosystem Catalog</a></li>
<li><a href="https://access.redhat.com/ecosystem/partner-resources">Partner Resources</a></li>
<li><a href="https://access.redhat.com/public-cloud">Red Hat in the Public Cloud</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Tools</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/insights/info/?intcmp=mm|t|c1|rhaidec2015&amp;">Red Hat Insights</a></li>
<li class="heading">Tools</li>
<li><a href="https://access.redhat.com/solution-engine">Solution Engine</a></li>
<li><a href="https://access.redhat.com/downloads/content/package-browser">Packages</a></li>
<li><a href="https://access.redhat.com/errata/">Errata</a></li>
<li class="heading">Customer Portal Labs</li>
<li><a href="https://access.redhat.com/labs/">Explore Labs</a></li>
<li><a href="https://access.redhat.com/labs/#?type=config">Configuration</a></li>
<li><a href="https://access.redhat.com/labs/#?type=deploy">Deployment</a></li>
<li><a href="https://access.redhat.com/labs/#?type=security">Security</a></li>
<li><a href="https://access.redhat.com/labs/#?type=troubleshoot">Troubleshooting</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Security</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/security/">Product Security Center</a></li>
<li class="heading">Security Updates</li>
<li><a href="https://access.redhat.com/security/security-updates/#/security-advisories">Security Advisories</a></li>
<li><a href="https://access.redhat.com/security/security-updates/#/cve">Red Hat CVE Database</a></li>
<li><a href="https://access.redhat.com/security/security-updates/#/security-labs">Security Labs</a></li>
<li class="heading">Resources</li>
<li><a href="https://access.redhat.com/security/overview/">Overview</a></li>
<li><a href="https://access.redhat.com/blogs/product-security">Security Blog</a></li>
<li><a href="https://www.redhat.com/security/data/metrics/">Security Measurement</a></li>
<li><a href="https://access.redhat.com/security/updates/classification/">Severity Ratings</a></li>
<li><a href="https://access.redhat.com/security/updates/backporting/">Backporting Policies</a></li>
<li><a href="https://access.redhat.com/security/team/key/">Product Signing (GPG) Keys</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Community</span></a>
<ul class="mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li class="heading">Customer Portal Community</li>
<li><a href="https://access.redhat.com/discussions?keyword=&amp;name=&amp;product=All&amp;category=All&amp;tags=All">Discussions</a></li>
<li><a href="https://access.redhat.com/blogs/">Blogs</a></li>
<li><a href="https://access.redhat.com/groups/">Private Groups</a></li>
<li><a href="https://access.redhat.com/community/">Community Activity</a></li>
<li class="heading">Customer Events</li>
<li><a href="https://access.redhat.com/convergence/">Red Hat Convergence</a></li>
<li><a href="http://www.redhat.com/summit/">Red Hat Summit</a></li>
<li class="heading">Stories</li>
<li><a href="https://access.redhat.com/subscription-value/">Red Hat Subscription Value</a></li>
<li><a href="https://access.redhat.com/you-asked-we-acted/">You Asked. We Acted.</a></li>
<li><a href="http://www.redhat.com/en/open-source">Open Source Communities</a></li>
</ul>
</li>
<li><a href="https://access.redhat.com/management/">Subscriptions</a></li>
<li><a href="https://access.redhat.com/downloads/">Downloads</a></li>
<li><a href="https://catalog.redhat.com/software/containers/explore/">Containers</a></li>
<li><a href="https://access.redhat.com/support/cases/">Support Cases</a></li>
<li>
<a href="#" class="has-subnav"><span>Account</span></a>
<ul class="utility mm-hide">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li class="mobile-accountLinksLoggedOut unauthenticated" style="display: block;"><a href="https://access.redhat.com/login?redirectTo=https%3A%2F%2Faccess.redhat.com%2Fsecurity%2Fcve%2FCVE-2019-14899" id="mobile-accountLogin">Log In</a></li>
<li class="mobile-accountLinksLoggedOut unauthenticated" style="display: block;"><a href="https://www.redhat.com/wapps/ugc/register.html">Register</a></li>
<li class="mobile-accountLinksLoggedIn authenticated">
<div class="account-info" id="mobile-accountUser">
<div class="account-name"><strong id="mobile-userFullName"></strong></div>
<div class="account-org"><span id="mobile-userOrg"></span></div>
<div class="account-number mobile-accountNumber"><span class="property">Red Hat Account Number:</span> <span class="value"></span></div>
</div>
</li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://www.redhat.com/wapps/ugc/protected/personalInfo.html">Account Details</a></li>
<!-- <li class="mobile-accountLinksLoggedIn authenticated"><a href="https://www.redhat.com/wapps/ugc/protected/prefs.html">Newsletter and Contact Preferences</a></li> -->
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://www.redhat.com/wapps/ugc/protected/usermgt/userList.html" class="user-management-link" hidden="hidden">User Management</a></li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://www.redhat.com/wapps/ugc/protected/account.html">Account Maintenance</a></li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://access.redhat.com/user">My Profile</a></li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://access.redhat.com/user" id="mobile-userNotificationsLink">Notifications</a></li>
<li class="mobile-accountLinksLoggedIn authenticated"><a href="https://access.redhat.com/help/">Help</a></li>
<li class="logout mobile-accountLinksLoggedIn authenticated"><a href="https://sso.redhat.com/auth/realms/redhat-external/logout?redirectUrl=https%3A%2F%2Faccess.redhat.com%2Flogout">Log Out</a></li>
</ul>
</li>
<li>
<a href="#" class="has-subnav"><span>Language</span></a>
<ul class="utility mm-hide" id="mobile-localesMenu">
<li aria-hidden="true"><a href="#" class="back">Back</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=en&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" id="mobile-en" class="selected">English</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=ko&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" id="mobile-ko">한국어</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=ja&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" id="mobile-ja">日本語</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=zh_CN&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" id="mobile-zh_CN">中文 (中国)</a></li>
</ul>
</li>
</ul>
</nav>
</div>
<!-- White Utility Menu for large screens -->
<div class="utility-wrap" aria-hidden="true">
<div class="utility-container">
<div class="utility-bar hidden-xs">
<div role="navigation" class="top-nav">
<ul>
<li id="nav-subscription" data-portal-tour-1="1"><a class="top-nav-subscriptions" href="https://access.redhat.com/management/">Subscriptions</a></li>
<li id="nav-downloads" data-portal-tour-1="2"><a class="top-nav-downloads" href="https://access.redhat.com/downloads/">Downloads</a></li>
<li id="nav-containers"><a class="top-nav-containers" href="https://catalog.redhat.com/software/containers/explore/">Containers</a></li>
<li id="nav-support" data-portal-tour-1="3"><a class="top-nav-support-cases" href="https://access.redhat.com/support/cases/">Support Cases</a></li>
</ul>
</div>
<div role="navigation" class="utility-nav">
<ul>
<li id="searchABTestHide">
<a class="btn-search" data-target="#site-search" title="Search" data-toggle="tooltip" data-placement="bottom">
<span class="web-icon-search" aria-label="search"></span>
<span class="link-text">Search</span>
</a>
</li>
<!-- AB Test -->
<li id="searchABTestShow">
<form id="topSearchFormABTest" name="topSearchFormABTest">
<label for="topSearchInputABTest" class="sr-only">Search</label>
<input id="topSearchInputABTest" name="keyword" placeholder="Search" type="text" autocomplete="off" autocorrect="off" autocapitalize="none" spellcheck="false" class="form-control">
<button type="submit" class="btn btn-app btn-sm btn-link"><span class="web-icon-search" aria-label="search"></span></button>
</form>
</li>
<!-- End of AB Test -->
<li>
<a class="btn-profile" data-target="#account-info" data-portal-tour-1="4a" title="Account" data-toggle="tooltip" data-placement="bottom">
<span class="web-icon-user" aria-label="log in"></span>
<span class="link-text">Log In</span>
<span class="account-user" id="accountUserName"></span>
</a>
</li>
<li>
<a class="btn-language" data-target="#language" data-portal-tour-1="6" title="Language" data-toggle="tooltip" data-placement="bottom">
<span class="web-icon-globe" aria-label="language"></span>
<span class="link-text">Language</span>
</a>
</li>
</ul>
</div>
</div>
<!-- Utility Tray -->
<div class="utility-tray-container">
<div class="utility-tray">
<div id="site-search" class="utility-link site-search">
<div class="content">
<form class="ng-pristine ng-valid topSearchForm" id="topSearchForm" name="topSearchForm" action="/search/browse/search/" method="get" enctype="application/x-www-form-urlencoded">
<cp-search-autocomplete class="push-bottom PFElement" path="/webassets/avalon/j/data.json" pfelement="" pfe-type="container"></cp-search-autocomplete>
<div class="input-group push-bottom">
<input class="form-control searchField" id="topSearchInput" name="keyword" placeholder="Enter your search term" type="text">
<span class="input-group-btn">
<button type="submit" class="btn btn-primary">Search</button>
</span>
</div>
<div>Or <a href="https://access.redhat.com/support/cases/#/troubleshoot">troubleshoot an issue</a>.</div>
</form>
</div>
</div>
<div id="account-info" class="utility-link account-info">
<div class="content">
<!-- Account Unauthenticated -->
<div id="accountLinksLoggedOut" class="unauthenticated" style="display: block;">
<h2 class="utility-header">Log in to Your Red Hat Account</h2>
<div class="row col-border-row">
<div class="col-sm-6 col-border">
<p><a href="https://access.redhat.com/login?redirectTo=https%3A%2F%2Faccess.redhat.com%2Fsecurity%2Fcve%2FCVE-2019-14899" id="accountLogin" class="btn btn-primary">Log In</a></p>
<p>Your Red Hat account gives you access to your profile, preferences, and services, depending on your status.</p>
</div>
<div class="col-sm-6 col-border col-border-left">
<p><a href="https://www.redhat.com/wapps/ugc/register.html" class="btn btn-primary">Register</a></p>
<p>If you are a new customer, register now for access to product evaluations and purchasing capabilities. </p>
<strong>Need access to an account?</strong><p>If your company has an existing Red Hat account, your organization administrator can grant you access.</p>
<p><a href="https://access.redhat.com/support/contact/customerService/">If you have any questions, please contact customer service.</a></p>
</div>
</div>
</div>
<!-- Account Authenticated -->
<div id="accountLinksLoggedIn" class="authenticated">
<h2 class="utility-header"><span id="userFirstName"></span></h2>
<div class="row col-border-row">
<div class="col-sm-6 col-border col-border-right">
<div class="account-info" id="accountUser">
<div class="avatar"><!-- placeholder--></div>
<div class="account-name"><strong id="userFullName"></strong></div>
<div class="account-org"><span id="userOrg"></span></div>
<div class="account-number accountNumber"><span class="property">Red Hat Account Number:</span> <span class="value"></span></div>
</div>
<div class="row account-settings">
<div class="col-md-6" data-portal-tour-1="4">
<h3>Red Hat Account</h3>
<ul class="reset">
<li><a href="https://www.redhat.com/wapps/ugc/protected/personalInfo.html">Account Details</a></li>
<!-- <li><a href="https://www.redhat.com/wapps/ugc/protected/prefs.html">Newsletter and Contact Preferences</a></li> -->
<li><a href="https://www.redhat.com/wapps/ugc/protected/usermgt/userList.html" class="user-management-link" hidden="hidden">User Management</a></li>
<li><a href="https://www.redhat.com/wapps/ugc/protected/account.html">Account Maintenance</a></li>
<li><a href="https://access.redhat.com/account-team">Account Team</a></li>
</ul>
</div>
<div class="col-md-6" data-portal-tour-1="5">
<h3>Customer Portal</h3>
<ul class="reset">
<li><a href="https://access.redhat.com/user">My Profile</a></li>
<li><a href="https://access.redhat.com/user" id="userNotificationsLink">Notifications</a></li>
<li><a href="https://access.redhat.com/help/">Help</a></li>
</ul>
</div>
</div>
</div>
<div class="col-sm-6 col-border">
<p>For your security, if you’re on a public computer and have finished using your Red Hat services, please be sure to log out.</p>
<p><a href="https://sso.redhat.com/auth/realms/redhat-external/logout?redirectUrl=https%3A%2F%2Faccess.redhat.com%2Flogout" id="accountLogout" class="btn btn-primary">Log Out</a></p>
</div>
</div>
</div>
</div>
</div>
<div id="language" class="utility-link language">
<div class="content">
<h2 class="utility-header">Select Your Language</h2>
<div class="row" id="localesMenu">
<div class="col-sm-2">
<ul class="reset">
<li><a href="https://access.redhat.com/changeLanguage?language=en&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" data-lang="en" id="en" class="selected">English</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=ko&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" data-lang="ko" id="ko">한국어</a></li>
</ul>
</div>
<div class="col-sm-2">
<ul class="reset">
<li><a href="https://access.redhat.com/changeLanguage?language=ja&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" data-lang="ja" id="ja">日本語</a></li>
<li><a href="https://access.redhat.com/changeLanguage?language=zh_CN&amp;redirectTo=https%3A//access.redhat.com/security/cve/CVE-2019-14899" data-lang="zh_CN" id="zh_CN">中文 (中国)</a></li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div id="scroll-anchor"></div>
<!-- Main Menu for large screens -->
<div class="header-nav visible-sm visible-md visible-lg" aria-hidden="true">
<div id="header-nav">
<div class="container">
<div class="row">
<div class="col-xs-12">
<a href="https://access.redhat.com/" class="logo">
<span class="sr-only">Red Hat Customer Portal</span>
<span class="logo-crop">
<svg aria-hidden="true" class="rh-logo" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 950 200">
<defs>
<style>
.rh-logo-type {
fill:#fff;
}
.rh-logo-hat {
fill:#e00;
}
</style>
</defs>
<title>Red Hat Customer Portal</title><g id="Two_lines" data-name="Two lines"><g id="Two_line_logo" data-name="Two line logo"><path class="rh-logo-type" d="M318.62,9.25h25.44c11.13,0,18.64,6.72,18.64,16.56,0,7.36-4.47,13-11.51,15.36l12.48,24.08h-9.29l-11.6-23H327v23h-8.4Zm8.4,7.36V35.33h16.33c6.55,0,10.87-3.76,10.87-9.36s-4.32-9.36-10.87-9.36Z"></path><path class="rh-logo-type" d="M387.5,66a21,21,0,0,1-21.36-21.12c0-11.76,9-21,20.4-21,11.2,0,19.68,9.28,19.68,21.28v2.32H374.06a13.74,13.74,0,0,0,13.76,11.68,15.84,15.84,0,0,0,10.32-3.6l5.13,5A24.33,24.33,0,0,1,387.5,66ZM374.14,41.49H398.3c-1.19-6.24-6-10.88-11.92-10.88C380.22,30.61,375.34,35,374.14,41.49Z"></path><path class="rh-logo-type" d="M445.18,61.41a19.23,19.23,0,0,1-12.48,4.48c-11.52,0-20.56-9.2-20.56-21a20.72,20.72,0,0,1,33-17V9.25l8-1.76V65.25h-7.92Zm-11.36-2.48a14.67,14.67,0,0,0,11.28-4.88V35.57a14.89,14.89,0,0,0-11.28-4.8,13.63,13.63,0,0,0-13.84,14A13.77,13.77,0,0,0,433.82,58.93Z"></path><path class="rh-logo-type" d="M480.22,9.25h8.4v24h29.76v-24h8.4v56h-8.4V40.85H488.62v24.4h-8.4Z"></path><path class="rh-logo-type" d="M534.38,53.57c0-7.68,6.24-12.4,16.48-12.4A28.75,28.75,0,0,1,562,43.41V39.09c0-5.76-3.44-8.64-9.92-8.64-3.76,0-7.6,1-12.64,3.44l-3-6c6.08-2.88,11.36-4.16,16.72-4.16,10.56,0,16.64,5.2,16.64,14.56v27H562V61.73A19.32,19.32,0,0,1,549.34,66C540.46,66,534.38,60.93,534.38,53.57Zm16.8,6.48A15.66,15.66,0,0,0,562,56.21v-7a21.15,21.15,0,0,0-10.48-2.48c-5.84,0-9.44,2.64-9.44,6.72C542.06,57.33,545.74,60.05,551.18,60.05Z"></path><path class="rh-logo-type" d="M582.7,31.25h-8.64V24.53h8.64V14.13l7.92-1.92V24.53h12v6.72h-12V53.33c0,4.16,1.68,5.68,6,5.68a15.72,15.72,0,0,0,5.84-1v6.72a26.5,26.5,0,0,1-7.6,1.2c-7.92,0-12.16-3.76-12.16-10.8Z"></path><path class="rh-logo-type" d="M361,132.21l7.59,7.52a30.76,30.76,0,0,1-23,10.32c-16.88,0-29.84-12.56-29.84-28.8s13-28.88,29.84-28.88c9,0,18.09,4.08,23.28,10.48l-7.83,7.76a19.52,19.52,0,0,0-15.45-7.6c-10.16,0-17.92,7.84-17.92,18.24A17.8,17.8,0,0,0,346,139.33,19.24,19.24,0,0,0,361,132.21Z"></path><path class="rh-logo-type" d="M383.74,131.81c0,5.36,3.44,8.8,8.64,8.8a10.05,10.05,0,0,0,8.65-4.16V107.57h11v41.68H401v-3.36a17.79,17.79,0,0,1-11.77,4.16c-9.68,0-16.48-6.88-16.48-16.64V107.57h11Z"></path><path class="rh-logo-type" d="M422.46,137c4.88,3.2,9.12,4.72,13.52,4.72,4.88,0,8.08-1.76,8.08-4.4,0-2.16-1.6-3.36-5.2-3.92l-8-1.2c-8.24-1.28-12.64-5.36-12.64-12.08,0-8.08,6.72-13.2,17.36-13.2a30.75,30.75,0,0,1,17.12,5.2l-5.28,7c-4.56-2.72-8.64-4-12.88-4-4,0-6.56,1.6-6.56,4.08,0,2.24,1.6,3.36,5.68,3.92l8,1.2c8.16,1.2,12.72,5.44,12.72,11.92,0,7.84-7.76,13.76-18.24,13.76-7.6,0-14.4-2-19.12-5.76Z"></path><path class="rh-logo-type" d="M464.7,116.77h-8.56v-9.2h8.56V96.93l11-2.48v13.12H487.5v9.2H475.66v18.48c0,3.92,1.52,5.36,5.76,5.36a16.86,16.86,0,0,0,5.84-1v9a34,34,0,0,1-8.48,1.28c-9.28,0-14.08-4.24-14.08-12.4Z"></path><path class="rh-logo-type" d="M512.86,106.77c12.48,0,22.24,9.52,22.24,21.68s-9.76,21.6-22.24,21.6-22.24-9.44-22.24-21.6S500.38,106.77,512.86,106.77Zm11.52,21.68c0-6.88-5-12.16-11.52-12.16s-11.52,5.28-11.52,12.16c0,6.72,5,12.08,11.52,12.08S524.38,135.17,524.38,128.45Z"></path><path class="rh-logo-type" d="M541.82,107.57h11v3.12a16.21,16.21,0,0,1,10.88-3.92A15,15,0,0,1,576.22,113,17.16,17.16,0,0,1,590,106.77c9.36,0,15.91,6.8,15.91,16.56v25.92h-11V124.93c0-5.28-3-8.72-7.83-8.72a9.37,9.37,0,0,0-8,4.16,18.89,18.89,0,0,1,.23,3v25.92h-11V124.93c0-5.28-3-8.72-7.84-8.72a9.3,9.3,0,0,0-7.76,3.76v29.28h-11Z"></path><path class="rh-logo-type" d="M634.78,150.05c-12.64,0-22.4-9.44-22.4-21.6a21.28,21.28,0,0,1,21.44-21.6c11.84,0,20.64,9.6,20.64,22.4v2.88h-31a12,12,0,0,0,11.84,8.72,13.12,13.12,0,0,0,9.2-3.36l7.2,6.56A25,25,0,0,1,634.78,150.05Zm-11.44-25.76h20.4c-1.36-5-5.36-8.4-10.16-8.4C628.54,115.89,624.7,119.17,623.34,124.29Z"></path><path class="rh-logo-type" d="M661.18,107.57h11v4.56a13.26,13.26,0,0,1,11.12-5.52,9.44,9.44,0,0,1,4.56,1v9.6a14,14,0,0,0-5.6-1.12,11,11,0,0,0-10.08,6.24v27h-11Z"></path><path class="rh-logo-type" d="M710.54,93.25h28.08c11,0,18.8,7.28,18.8,17.6,0,10-7.92,17.28-18.8,17.28H722.14v21.12h-11.6Zm11.6,10v15.28h15.2c5,0,8.32-3,8.32-7.6s-3.28-7.68-8.32-7.68Z"></path><path class="rh-logo-type" d="M782.14,106.77c12.48,0,22.24,9.52,22.24,21.68s-9.76,21.6-22.24,21.6-22.24-9.44-22.24-21.6S769.66,106.77,782.14,106.77Zm11.52,21.68c0-6.88-5-12.16-11.52-12.16s-11.52,5.28-11.52,12.16c0,6.72,5,12.08,11.52,12.08S793.66,135.17,793.66,128.45Z"></path><path class="rh-logo-type" d="M811.1,107.57h11v4.56a13.26,13.26,0,0,1,11.12-5.52,9.44,9.44,0,0,1,4.56,1v9.6a14,14,0,0,0-5.6-1.12,11,11,0,0,0-10.08,6.24v27h-11Z"></path><path class="rh-logo-type" d="M850,116.77h-8.56v-9.2H850V96.93l11-2.48v13.12h11.84v9.2H860.94v18.48c0,3.92,1.52,5.36,5.76,5.36a16.86,16.86,0,0,0,5.84-1v9a34,34,0,0,1-8.48,1.28c-9.28,0-14.08-4.24-14.08-12.4Z"></path><path class="rh-logo-type" d="M876.22,137.17c0-7.92,6.4-12.64,17.12-12.64a33.71,33.71,0,0,1,10.16,1.6v-3c0-4.8-3-7.28-8.8-7.28-3.52,0-7.44,1.12-12.72,3.44l-4-8.08a43.46,43.46,0,0,1,18.56-4.48c11.28,0,17.76,5.6,17.76,15.44v27H903.5v-2.88a19.81,19.81,0,0,1-12.08,3.6C882.46,150,876.22,144.77,876.22,137.17Zm18.08,5a15.78,15.78,0,0,0,9.2-2.64v-6.24a24.22,24.22,0,0,0-8.8-1.52c-5,0-8,2-8,5.2S889.66,142.13,894.3,142.13Z"></path><path class="rh-logo-type" d="M933.58,149.25h-11v-56l11-2.4Z"></path><g id="Hat_icon" data-name="Hat icon"><path id="Red_hat" data-name="Red hat" class="rh-logo-hat" d="M129,92.24c12.5,0,30.61-2.58,30.61-17.46a14,14,0,0,0-.31-3.42L151.82,39c-1.72-7.12-3.23-10.35-15.74-16.6-9.7-5-30.82-13.15-37.07-13.15-5.83,0-7.55,7.54-14.45,7.54-6.68,0-11.64-5.6-17.89-5.6-6,0-9.92,4.1-12.93,12.5,0,0-8.41,23.72-9.49,27.16A6.43,6.43,0,0,0,44,52.79C44,62,80.32,92.24,129,92.24Zm32.55-11.42c1.72,8.19,1.72,9.05,1.72,10.13,0,14-15.73,21.77-36.43,21.77-46.77,0-87.73-27.37-87.73-45.48a18.32,18.32,0,0,1,1.51-7.33C23.77,60.77,2,63.79,2,83c0,31.48,74.59,70.28,133.65,70.28,45.27,0,56.7-20.48,56.7-36.65C192.35,103.88,181.35,89.44,161.52,80.82Z"></path><path class="rh-logo-band" id="Black_band" data-name="Black band" d="M161.52,80.82c1.72,8.19,1.72,9.05,1.72,10.13,0,14-15.73,21.77-36.43,21.77-46.77,0-87.73-27.37-87.73-45.48a18.32,18.32,0,0,1,1.51-7.33l3.66-9.06A6.43,6.43,0,0,0,44,52.79C44,62,80.32,92.24,129,92.24c12.5,0,30.61-2.58,30.61-17.46a14,14,0,0,0-.31-3.42Z"></path></g><path id="Dividing_line" data-name="Dividing line" class="rh-logo-type" d="M255.47,160.75a2.25,2.25,0,0,1-2.25-2.25V4.25a2.25,2.25,0,0,1,4.5,0V158.5A2.25,2.25,0,0,1,255.47,160.75Z"></path></g></g>
</svg>
</span>
</a>
<nav class="primary-nav" style="display: block;">
<ul>
<li id="nav-products"><a class="products" data-link="mega" data-target="products-menu" href="https://access.redhat.com/products/" id="products-menu">Products &amp; Services</a></li>
<li id="nav-tools"><a class="tools" data-link="mega" data-target="tools-menu" href="https://access.redhat.com/labs/" id="tools-menu">Tools</a></li>
<li id="nav-security"><a class="security" data-link="mega" data-target="security-menu" href="https://access.redhat.com/security/" id="security-menu">Security</a></li>
<li id="nav-community"><a class="community" data-link="mega" data-target="community-menu" href="https://access.redhat.com/community/" id="community-menu">Community</a></li>
</ul>
</nav>
</div>
</div>
</div>
</div>
</div>
<!-- Main Mega Menu for large screens -->
<div class="mega-wrap visible-sm visible-md visible-lg" aria-hidden="true">
<nav class="mega">
<div class="container">
<div class="mega-menu-wrap">
<!-- Products Menu -->
<div aria-labelledby="products-menu" class="products-menu mega-menu" data-eh="mega-menu" role="navigation" style="height: 603px;">
<div class="row">
<div class="col-md-6 col-sm-8">
<div class="root clearfix" data-portal-tour-1="7">
<ul class="subnav subnav-root">
<li data-target="infrastructure-menu" class="active">
<h3>Infrastructure and Management</h3>
</li>
<li data-target="cloud-menu">
<h3>Cloud Computing</h3>
</li>
<li data-target="storage-menu">
<h3>Storage</h3>
</li>
<li data-target="jboss-dev-menu">
<h3>Runtimes</h3>
</li>
<li data-target="jboss-int-menu">
<h3>Integration and Automation</h3>
</li>
</ul>
<div class="subnav subnav-child" data-eh="subnav-child" data-menu-local="infrastructure-menu" style="display: block; height: 532px;">
<ul>
<li>
<a href="https://access.redhat.com/products/red-hat-enterprise-linux/">Red Hat Enterprise Linux</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-virtualization/">Red Hat Virtualization</a>
</li>
<li>
<a href="https://access.redhat.com/products/identity-management/">Red Hat Identity Management</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-directory-server/">Red Hat Directory Server</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-certificate-system/">Red Hat Certificate System</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-satellite/">Red Hat Satellite</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-subscription-management/">Red Hat Subscription Management</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-update-infrastructure/">Red Hat Update Infrastructure</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-insights/">Red Hat Insights</a>
</li>
<li><a href="https://access.redhat.com/products/red-hat-ansible-automation-platform/">Red Hat Ansible Automation Platform</a></li>
</ul>
</div>
<div class="subnav subnav-child" data-eh="subnav-child" data-menu-local="cloud-menu" style="height: 532px;">
<ul>
<li>
<a href="https://access.redhat.com/products/red-hat-cloudforms/">Red Hat CloudForms</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-openstack-platform/">Red Hat OpenStack Platform</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-openshift-container-platform/">Red Hat OpenShift Container Platform</a>
</li>
<li>
<a href="https://access.redhat.com/products/openshift-online-red-hat/">Red Hat OpenShift Online</a>
</li>
<li>
<a href="https://access.redhat.com/products/openshift-dedicated-red-hat/">Red Hat OpenShift Dedicated</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-advanced-cluster-management-for-kubernetes/">Red Hat Advanced Cluster Management for Kubernetes</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-quay/">Red Hat Quay</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-codeready-workspaces/">Red Hat CodeReady Workspaces</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-openshift-service-aws">Red Hat OpenShift Service on AWS</a>
</li>
</ul>
</div>
<div class="subnav subnav-child" data-eh="subnav-child" data-menu-local="storage-menu" style="height: 532px;">
<ul>
<li>
<a href="https://access.redhat.com/products/red-hat-storage/">Red Hat Gluster Storage</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-hyperconverged-infrastructure/">Red Hat Hyperconverged Infrastructure</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-ceph-storage/">Red Hat Ceph Storage</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-openshift-container-storage">Red Hat Openshift Container Storage</a>
</li>
</ul>
</div>
<div class="subnav subnav-child" data-eh="subnav-child" data-menu-local="jboss-dev-menu" style="height: 532px;">
<ul>
<li>
<a href="https://access.redhat.com/products/red-hat-runtimes/">Red Hat Runtimes</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-enterprise-application-platform/">Red Hat JBoss Enterprise Application Platform</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-data-grid/">Red Hat Data Grid</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-web-server/">Red Hat JBoss Web Server</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-single-sign-on/">Red Hat Single Sign On</a>
</li>
<li>
<a href="https://access.redhat.com/products/spring-boot/">Red Hat support for Spring Boot</a>
</li>
<li>
<a href="https://access.redhat.com/products/nodejs/">Red Hat build of Node.js</a>
</li>
<li>
<a href="https://access.redhat.com/products/thorntail/">Red Hat build of Thorntail</a>
</li>
<li>
<a href="https://access.redhat.com/products/eclipse-vertx/">Red Hat build of Eclipse Vert.x</a>
</li>
<li>
<a href="https://access.redhat.com/products/openjdk/">Red Hat build of OpenJDK</a>
</li>
<li>
<a href="https://access.redhat.com/products/quarkus/">Red Hat build of Quarkus</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-codeready-studio/">Red Hat CodeReady Studio</a>
</li>
</ul>
</div>
<!-- <div class="subnav subnav-child" data-eh="subnav-child" data-menu-local="jboss-int-menu">
<ul>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-data-virtualization/">Red Hat JBoss Data Virtualization</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-fuse/">Red Hat Fuse</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-amq/">Red Hat AMQ</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-process-automation-manager/">Red Hat Process Automation Manager</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-decision-manager/">Red Hat Decision Manager</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-3scale/">Red Hat 3scale API Management</a>
</li>
</ul>
</div> -->
<div class="subnav subnav-child" data-eh="subnav-child" data-menu-local="jboss-int-menu" style="height: 532px;">
<ul class="border-bottom" id="portal-menu-border-bottom">
<li>
<a href="https://access.redhat.com/products/red-hat-integration/">Red Hat Integration</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-fuse/">Red Hat Fuse</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-amq/">Red Hat AMQ</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-3scale/">Red Hat 3scale API Management</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-jboss-data-virtualization/">Red Hat JBoss Data Virtualization</a>
</li>
</ul>
<ul>
<li>
<a href="https://access.redhat.com/products/red-hat-process-automation/">Red Hat Process Automation</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-process-automation-manager/">Red Hat Process Automation Manager</a>
</li>
<li>
<a href="https://access.redhat.com/products/red-hat-decision-manager/">Red Hat Decision Manager</a>
</li>
</ul>
</div>
</div>
<a href="https://access.redhat.com/products" class="btn btn-primary">View All Products</a>
</div>
<div class="col-md-6 col-sm-4 pull-right" data-portal-tour-1="8">
<div class="row">
<div class="col-md-6">
<ul>
<li><a href="https://access.redhat.com/support" class="cta-link cta-link-darkbg">Support</a></li>
<li><a href="https://access.redhat.com/support/offerings/production/">Production Support</a></li>
<li><a href="https://access.redhat.com/support/offerings/developer/">Development Support</a></li>
<li><a href="https://access.redhat.com/product-life-cycles/">Product Life Cycles</a></li>
</ul>
<h4 class="nav-title">Services</h4>
<ul>
<li><a href="https://www.redhat.com/en/services/consulting">Consulting</a></li>
<li><a href="https://access.redhat.com/support/offerings/tam/">Technical Account Management</a></li>
<li><a href="https://www.redhat.com/en/services/training-and-certification">Training &amp; Certifications</a></li>
</ul>
</div>
<div class="col-md-6">
<ul>
<li><a href="https://access.redhat.com/documentation" class="cta-link cta-link-darkbg">Documentation</a></li>
<li><a href="https://access.redhat.com/documentation/en/red_hat_enterprise_linux">Red Hat Enterprise Linux</a></li>
<li><a href="https://access.redhat.com/documentation/en/red_hat_jboss_enterprise_application_platform">Red Hat JBoss Enterprise Application Platform</a></li>
<li><a href="https://access.redhat.com/documentation/en/red_hat_openstack_platform">Red Hat OpenStack Platform</a></li>
<li><a href="https://access.redhat.com/documentation/en/openshift_container_platform">Red Hat OpenShift Container Platform</a></li>
</ul>
<ul>
<li><a href="https://catalog.redhat.com/" class="cta-link cta-link-darkbg">Ecosystem Catalog</a></li>
<li><a href="https://access.redhat.com/public-cloud">Red Hat in the Public Cloud</a></li>
<li><a href="https://access.redhat.com/ecosystem/partner-resources">Partner Resources</a></li>
</ul>
</div>
</div>
</div>
</div>
</div>
<!-- Tools Menu -->
<div aria-labelledby="tools-menu" class="tools-menu mega-menu" data-eh="mega-menu" role="navigation" style="height: 603px;">
<div class="row" data-portal-tour-1="9">
<div class="col-sm-12">
<div class="row">
<div class="col-sm-4">
<h3 class="nav-title">Tools</h3>
<ul>
<li><a href="https://access.redhat.com/solution-engine">Solution Engine</a></li>
<li><a href="https://access.redhat.com/downloads/content/package-browser">Packages</a></li>
<li><a href="https://access.redhat.com/errata/">Errata</a></li>
</ul>
</div>
<div class="col-sm-4">
<ul class="list-flat">
<li><a href="https://access.redhat.com/labs/" class="cta-link cta-link-darkbg">Customer Portal Labs</a></li>
<li><a href="https://access.redhat.com/labs/#?type=config">Configuration</a></li>
<li><a href="https://access.redhat.com/labs/#?type=deploy">Deployment</a></li>
<li><a href="https://access.redhat.com/labs/#?type=security">Security</a></li>
<li><a href="https://access.redhat.com/labs/#?type=troubleshoot">Troubleshooting</a></li>
</ul>
</div>
<div class="col-sm-4">
<div class="card card-dark-grey">
<h4 class="card-heading">Red Hat Insights</h4>
<p class="text-white">Increase visibility into IT operations to detect and resolve technical issues before they impact your business.</p>
<ul class="list-flat rh-l-grid rh-m-gutters rh-m-all-6-col-on-md">
<li><a href="https://www.redhat.com/en/technologies/management/insights" class="cta-link cta-link-md cta-link-darkbg">Learn more</a></li>
<li><a href="https://cloud.redhat.com/insights" class="cta-link cta-link-md cta-link-darkbg">Go to Insights</a></li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
<!-- Security Menu -->
<div aria-labelledby="security-menu" class="security-menu mega-menu" data-eh="mega-menu" role="navigation" style="height: 603px;">
<div class="row">
<div class="col-sm-12 basic" data-portal-tour-1="10">
<div class="row">
<div class="col-sm-4">
<h2 class="nav-title">Red Hat Product Security Center</h2>
<p class="text-white">Engage
with our Red Hat Product Security team, access security updates, and
ensure your environments are not exposed to any known security
vulnerabilities.</p>
<p><a href="https://access.redhat.com/security/" class="btn btn-primary">Product Security Center</a></p>
</div>
<div class="col-sm-4">
<h2 class="nav-title">Security Updates</h2>
<ul>
<li><a href="https://access.redhat.com/security/security-updates/#/security-advisories">Security Advisories</a></li>
<li><a href="https://access.redhat.com/security/security-updates/#/cve">Red Hat CVE Database</a></li>
<li><a href="https://access.redhat.com/security/security-updates/#/security-labs">Security Labs</a></li>
</ul>
<p class="text-white">Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.</p>
<ul>
<li class="more-link"><a href="https://access.redhat.com/security/vulnerability">View Responses</a></li>
</ul>
</div>
<div class="col-sm-4">
<h2 class="nav-title">Resources</h2>
<ul>
<li><a href="https://access.redhat.com/security/overview/">Overview</a></li>
<li><a href="https://www.redhat.com/en/blog/channel/security">Security Blog</a></li>
<li><a href="https://www.redhat.com/security/data/metrics/">Security Measurement</a></li>
<li><a href="https://access.redhat.com/security/updates/classification/">Severity Ratings</a></li>
<li><a href="https://access.redhat.com/security/updates/backporting/">Backporting Policies</a></li>
<li><a href="https://access.redhat.com/security/team/key/">Product Signing (GPG) Keys</a></li>
</ul>
</div>
</div>
</div>
</div>
</div>
<!-- Community Menu -->
<div aria-labelledby="community-menu" class="community-menu mega-menu" data-eh="mega-menu" role="navigation" style="height: 603px;">
<div class="row">
<div class="col-sm-12 basic" data-portal-tour-1="11">
<div class="row">
<div class="col-sm-4">
<h2 class="nav-title">Customer Portal Community</h2>
<ul>
<li><a href="https://access.redhat.com/discussions?keyword=&amp;name=&amp;product=All&amp;category=All&amp;tags=All">Discussions</a></li>
<li><a href="https://access.redhat.com/blogs/">Blogs</a></li>
<li><a href="https://access.redhat.com/groups/">Private Groups</a></li>
<p class="push-top"><a href="https://access.redhat.com/community/" class="btn btn-primary">Community Activity</a></p>
</ul>
</div>
<div class="col-sm-4">
<h2 class="nav-title">Customer Events</h2>
<ul>
<li><a href="https://access.redhat.com/convergence/">Red Hat Convergence</a></li>
<li><a href="http://www.redhat.com/summit/">Red Hat Summit</a></li>
</ul>
</div>
<div class="col-sm-4">
<h2 class="nav-title">Stories</h2>
<ul>
<li><a href="https://access.redhat.com/subscription-value/">Red Hat Subscription Value</a></li>
<li><a href="https://access.redhat.com/you-asked-we-acted/">You Asked. We Acted.</a></li>
<li><a href="http://www.redhat.com/en/open-source">Open Source Communities</a></li>
</ul>
</div>
</div>
</div>
<!--<a href="https://access.redhat.com/community/" class="btn btn-primary">Explore Community</a>-->
</div>
</div>
</div>
</div>
</nav>
</div>
<!--[if IE 8]>
<div class="portal-messages">
<div class="alert alert-warning alert-portal alert-w-icon">
<span class="icon-warning alert-icon" aria-hidden="true"></span>
You are using an unsupported web browser. Update to a supported browser for the best experience. <a href="/announcements/2120951">Read the announcement</a>.
</div>
</div>
<![endif]-->
<!--[if IE 9]>
<div class="portal-messages">
<div class="alert alert-warning alert-portal alert-w-icon">
<span class="icon-warning alert-icon" aria-hidden="true"></span>
As of March 1, 2016, the Red Hat Customer Portal will no longer support Internet Explorer 9. See our new <a href="/help/browsers">browser support policy</a> for more information.
</div>
</div>
<![endif]-->
<div id="site-section"></div>
</header>
<!--googleon: all-->
<main id="cp-main" class="portal-content-area">
<div id="cp-content" class="main-content">
<noscript>
<strong>We're sorry but cve-details doesn't work properly without JavaScript enabled. Please enable it to continue.</strong>
</noscript>
<div id="cve-details-app" data-test="test-div"><!----><!----><!----><div><div id="cve-overview" class="band band-alt band-first"><div class="container"><div class="pfe-l-grid pfe-m-gutters"><div class="pfe-m-7-col-on-md"><h1 class="headline" style="margin-top: 0px;">CVE-2019-14899</h1><p class="cve-public-date">Public on <pfe-datetime type="local" day="numeric" month="long" year="numeric" datetime="2019-12-04T15:00:00+00:00" class="PFElement" pfelement=""></pfe-datetime></p><!----></div><!----></div><div class="pfe-l-grid pfe-m-gutters push-top"><div id="stat-card-impact" class="stat-card-left pfe-m-4-col-on-md"><span class="stat-number cve-impact-important"><span class="rh-icon-protected md-icon"></span></span><span class="stat-title white">Important Impact<a href="https://access.redhat.com/security/updates/classification/" class="cta"><span class="stat-subtitle">What does this mean?</span></a></span></div><div class="pfe-m-4-col-on-md"><a href="https://access.redhat.com/security/cve/CVE-2019-14899#cve-cvss-v3" class="stat-card-left"><span class="stat-number">7.4</span><span class="stat-title white">CVSS v3 Base Score<span class="stat-subtitle">CVSS Score Breakdown</span></span></a></div><!----></div></div></div><div class="band"><div class="container"><section><div class="pfe-l-grid pfe-m-gutters"><div class="pfe-m-7-col-on-md"><section id="cve-details-description"><h2>Description</h2><!----><div><p>A
flaw was found in openvpn. A malicous access point or adjacent user can
determine if a connected user is using a VPN by making positive
inferences about the websites they are visiting, and determining the
correct sequence and acknowledgement numbers in use, which allows the
attacker to inject data into the TCP stream. With this information, an
attacker could hijack an active connection inside the VPN tunnel. The
highest threat from this vulnerability is to data confidentiality and
integrity as well as system availability.</p></div></section><!----><section id="cve-details-statement"><h2>Statement</h2><div><pfe-markdown class="PFElement" pfelement="" has_default=""><div pfe-markdown-container="" style="display: none;">This
issue did not affect Red Hat Enterprise Linux 5, 6, 7, and 8 as openvpn
package is currently not provided in any of our supported products.</div><div pfe-markdown-render=""><p>This
issue did not affect Red Hat Enterprise Linux 5, 6, 7, and 8 as openvpn
package is currently not provided in any of our supported products.</p>
</div></pfe-markdown></div></section><!----></div><div class="pfe-m-1-col-on-md hidden-xs"></div><div class="pfe-m-4-col-on-md"><div class="card card-bordered"><h3 class="card-heading">Additional Information</h3><ul class="list-caret push-top-narrow"><li><a href="https://bugzilla.redhat.com/show_bug.cgi?id=1774905">Bugzilla 1774905</a>:
CVE-2019-14899 VPN: an attacker can inject data into the TCP stream
which allows a hijack of active connections inside the VPN tunnel</li><li><a href="http://cwe.mitre.org/data/definitions/300.html">CWE-300</a>: Channel Accessible by Non-Endpoint</li><li><a href="https://access.redhat.com/security/cve/CVE-2019-14899#cve-faq" class="">FAQ</a>: Frequently asked questions about CVE-2019-14899</li></ul></div></div></div></section><section id="cve-affected-packages" class="push-top-wide"><h2>Affected Packages and Issued Red Hat Security Errata</h2><div data-v-f0e114d2="" class="table-data-wrapper push-top" rhbreakdown="[object Object]"><div data-v-f0e114d2="" id="DataTables_Table_0_wrapper" class="dataTables_wrapper no-footer"><div id="DataTables_Table_0_wrapper" class="dataTables_wrapper no-footer"><div class="table-data-top" style="display: none;"><div id="DataTables_Table_0_filter" class="dataTables_filter"><label>Search:<input type="search" class="" placeholder="" aria-controls="DataTables_Table_0"></label></div></div><table data-v-f0e114d2="" id="DataTables_Table_0" role="grid" aria-describedby="DataTables_Table_0_info" class="table-data table table-cp table-bordered table-striped dataTable no-footer"><thead data-v-f0e114d2=""><tr data-v-f0e114d2="" role="row"><th data-v-f0e114d2="" id="th-platform-b" scope="col" tabindex="0" aria-controls="DataTables_Table_0" rowspan="1" colspan="1" aria-label="Platform: activate to sort column ascending" class="sorting" style="width: 234px;">Platform</th><th data-v-f0e114d2="" id="th-package-b" scope="col" tabindex="0" aria-controls="DataTables_Table_0" rowspan="1" colspan="1" aria-label="Package: activate to sort column ascending" class="sorting_desc" style="width: 165px;" aria-sort="descending">Package</th><th data-v-f0e114d2="" id="th-state-b" scope="col" tabindex="0" aria-controls="DataTables_Table_0" rowspan="1" colspan="1" aria-label="State: activate to sort column ascending" class="sorting" style="width: 124px;">State</th><th data-v-f0e114d2="" id="th-errata-b" scope="col" tabindex="0" aria-controls="DataTables_Table_0" rowspan="1" colspan="1" aria-label="Errata: activate to sort column ascending" class="sorting" style="width: 134px;">Errata</th><th data-v-f0e114d2="" id="th-release-b" scope="col" tabindex="0" aria-controls="DataTables_Table_0" rowspan="1" colspan="1" aria-label="Release Date: activate to sort column ascending" class="sorting" style="width: 226px;">Release Date</th></tr></thead><tbody data-v-f0e114d2=""><tr class="odd"><td colspan="5" class="dataTables_empty" valign="top">No data available in table</td></tr></tbody></table><div class="table-data-bottom" style="display: none;"><div class="dataTables_length" id="DataTables_Table_0_length"><label>Show <select name="DataTables_Table_0_length" aria-controls="DataTables_Table_0" class=""><option value="10" selected="selected">10</option><option value="25">25</option><option value="50">50</option><option value="100">100</option></select> entries</label></div><div class="dataTables_paginate paging_full_numbers" id="DataTables_Table_0_paginate"><a class="paginate_button first disabled" aria-controls="DataTables_Table_0" data-dt-idx="0" tabindex="-1" id="DataTables_Table_0_first">First</a><a class="paginate_button previous disabled" aria-controls="DataTables_Table_0" data-dt-idx="1" tabindex="-1" id="DataTables_Table_0_previous">Previous</a><span></span><a class="paginate_button next disabled" aria-controls="DataTables_Table_0" data-dt-idx="2" tabindex="-1" id="DataTables_Table_0_next">Next</a><a class="paginate_button last" aria-controls="DataTables_Table_0" data-dt-idx="3" tabindex="0" id="DataTables_Table_0_last">Last</a></div><div class="dataTables_info" id="DataTables_Table_0_info" role="status" aria-live="polite">Showing 0 to 0 of 0 entries</div></div></div></div><div data-v-f0e114d2="" class="clear"></div><div data-v-f0e114d2="" class="pfe-l-grid pfe-m-gutters pfe-m-all-9-col-on-md"><p data-v-f0e114d2="" id="package-disclaimer" class="push-top-narrow">Unless
explicitly stated as not affected, all previous versions of packages in
any minor update stream of a product listed here should be assumed
vulnerable, although may not have been subject to full analysis.</p></div></div></section><section id="cve-cvss" class="push-top-wide"><h2>Common Vulnerability Scoring System (CVSS) Score Details</h2><!----><div><p>The following CVSS metrics and score provided are preliminary and subject to review.</p><!----><div id="cve-cvss-v3"><div class="pfe-l-grid pfe-m-gutters"><div class="pfe-m-7-col-on-md"><h3>CVSS v3 Score Breakdown</h3><table class="table table-cp"><thead><tr><th id="th-cve-category-type" scope="col"></th><th id="th-cve-rh" scope="col">Red Hat</th><th id="th-cve-NVD" scope="col">NVD</th></tr></thead><!----><!----><tbody><tr><th id="th-cve-category1" headers="th-cve-category-type">CVSS v3 Base Score</th><td headers="th-cve-category1 th-cve-rh">7.4</td><td headers="th-cve-category1 th-cve-NVD">7.4</td></tr><tr><th id="th-cve-category2" headers="th-cve-category-type">Attack Vector</th><td headers="th-cve-category2 th-cve-rh">Adjacent Network</td><td headers="th-cve-category2 th-cve-NVD">Adjacent Network</td></tr><tr><th id="th-cve-category3" headers="th-cve-category-type">Attack Complexity</th><td headers="th-cve-category3 th-cve-rh">Low</td><td headers="th-cve-category3 th-cve-NVD">Low</td></tr><tr><th id="th-cve-category4" headers="th-cve-category-type">Privileges Required</th><td headers="th-cve-category4 th-cve-rh">Low</td><td headers="th-cve-category4 th-cve-NVD">Low</td></tr><tr><th id="th-cve-category5" headers="th-cve-category-type">User Interaction</th><td headers="th-cve-category5 th-cve-rh">Required</td><td headers="th-cve-category5 th-cve-NVD">Required</td></tr><tr><th id="th-cve-category6" headers="th-cve-category-type">Scope</th><td headers="th-cve-category6 th-cve-rh">Unchanged</td><td headers="th-cve-category6 th-cve-NVD">Unchanged</td></tr><tr><th id="th-cve-category7" headers="th-cve-category-type">Confidentiality</th><td headers="th-cve-category7 th-cve-rh">High</td><td headers="th-cve-category7 th-cve-NVD">High</td></tr><tr><th id="th-cve-category8" headers="th-cve-category-type">Integrity Impact</th><td headers="th-cve-category8 th-cve-rh">High</td><td headers="th-cve-category8 th-cve-NVD">High</td></tr><tr><th id="th-cve-category9" headers="th-cve-category-type">Availability Impact</th><td headers="th-cve-category9 th-cve-rh">High</td><td headers="th-cve-category9 th-cve-NVD">High</td></tr></tbody><!----></table></div><div id="package-vectors" class="pfe-m-5-col-on-md"><h3>CVSS v3 Vector</h3><p><span class="cve-vector">Red Hat: </span><span class="cve-vector-compare"><span class="vector-highlight">CVSS:3.0</span>/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</span></p><p><span class="cve-vector">NVD: </span><span class="cve-vector-compare"><span class="vector-highlight">CVSS:3.1</span>/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</span></p><!----></div></div></div></div></section><!----><section id="cve-references" class="push-top-wide"><h2>External References</h2><div class="pfe-l-grid pfe-m-gutters pfe-m-all-9-col-on-md"><pfe-markdown class="PFElement" pfelement="" has_default=""><div pfe-markdown-container="" style="display: none;">https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/</div><div pfe-markdown-render=""><p><a href="https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/">https://openvpn.net/security-advisory/no-flaws-found-in-openvpn-software/</a></p>
</div></pfe-markdown></div></section><section id="cve-faq" class="push-top-wide"><h2>Frequently Asked Questions</h2><div class="pfe-l-grid pfe-m-all-8-col-on-md push-top"><pfe-accordion class="PFElement" pfelement="" has_default="" pfe-type="container" role="tablist" defined=""><pfe-accordion-header class="PFElement" pfelement="" role="heading" pfe-id="pfe-accordion-header-znvw2eudv" aria-controls="pfe-accordion-panel-lhs2ryb8t"><h3>Why is Red Hat's CVSS v3 score or Impact different from other vendors?</h3></pfe-accordion-header><pfe-accordion-panel class="PFElement" pfelement="" role="region" pfe-id="pfe-accordion-panel-lhs2ryb8t" aria-labelledby="pfe-accordion-header-znvw2eudv">For
open source software shipped by multiple vendors, the CVSS base scores
may vary for each vendor's version depending on the version they ship,
how they ship it, the platform, and even how the software is compiled.
This makes scoring of vulnerabilities difficult for third-party
vulnerability databases such as NVD that only provide a single CVSS base
score for each vulnerability. Red Hat scores reflect how a
vulnerability affects our products specifically.<br><br>For more information, see <a href="https://access.redhat.com/solutions/762393">https://access.redhat.com/solutions/762393</a>.</pfe-accordion-panel><pfe-accordion-header class="PFElement" pfelement="" role="heading" pfe-id="pfe-accordion-header-ptgvfy0w3" aria-controls="pfe-accordion-panel-ozfflu3k9"><h3>My product is listed as "Under investigation" or "Affected", when will Red Hat release a fix for this vulnerability?</h3></pfe-accordion-header><pfe-accordion-panel class="PFElement" pfelement="" role="region" pfe-id="pfe-accordion-panel-ozfflu3k9" aria-labelledby="pfe-accordion-header-ptgvfy0w3"><ul><li>"Under
investigation" doesn't necessarily mean that the product is affected by
this vulnerability. It only means that our Analysis Team is still
working on determining whether the product is affected and how it is
affected.</li><li>"Affected" means that our Analysis Team has determined
that this product is affected by this vulnerability and might release a
fix to address this in the near future.</li></ul></pfe-accordion-panel><pfe-accordion-header class="PFElement" pfelement="" role="heading" pfe-id="pfe-accordion-header-1svvfji6h" aria-controls="pfe-accordion-panel-0yjgjr8xh"><h3>What can I do if my product is listed as "Will not fix"?</h3></pfe-accordion-header><pfe-accordion-panel class="PFElement" pfelement="" role="region" pfe-id="pfe-accordion-panel-0yjgjr8xh" aria-labelledby="pfe-accordion-header-1svvfji6h">This depends mostly on the <a href="https://access.redhat.com/security/updates/classification/">Impact</a> of the vulnerability and the <a href="https://access.redhat.com/support/policy/update_policies">Life Cycle</a> phase in which your product is currently in. Overall, you have the following options:<ul><li>Upgrade to a supported product version that includes a fix for this vulnerability (recommended)</li><li>Apply a mitigation (if one exists)</li><li>Open a <a href="https://access.redhat.com/support/cases/#/new">support case</a> to request a prioritization of releasing a fix for this vulnerability</li></ul></pfe-accordion-panel><pfe-accordion-header class="PFElement" pfelement="" role="heading" pfe-id="pfe-accordion-header-5gslfesep" aria-controls="pfe-accordion-panel-f8iph4efz"><h3>Why
is my security scanner reporting my product as vulnerable to this
vulnerability even though my product version is fixed or not affected?</h3></pfe-accordion-header><pfe-accordion-panel class="PFElement" pfelement="" role="region" pfe-id="pfe-accordion-panel-f8iph4efz" aria-labelledby="pfe-accordion-header-5gslfesep">In
order to maintain code stability and compatibility, Red Hat usually
does not rebase packages to entirely new versions. Instead, we <a href="https://access.redhat.com/security/updates/backporting">backport</a>
fixes and new features to an older version of the package we
distribute. This can result in some security scanners that only consider
the package version to report the package as vulnerable. To avoid this,
we suggest that you use an OVAL-compatible security scanner like
OpenSCAP.<br><br>For more information, see <a href="https://access.redhat.com/blogs/766093/posts/2998921">https://access.redhat.com/blogs/766093/posts/2998921</a>.</pfe-accordion-panel></pfe-accordion></div></section><section id="cve-footer" class="push-top"><p>This page is generated automatically and has not been checked for errors or omissions.</p><p>For clarification or corrections please contact <a href="https://access.redhat.com/security/team/contact/">Red Hat Product Security</a>.</p><p class="push-top-narrow">Last Modifed: <pfe-datetime type="local" day="numeric" month="long" year="numeric" hour="numeric" minute="numeric" second="numeric" timestamp="1588777803" class="PFElement" pfelement=""></pfe-datetime></p><p>CVE description copyright © 2021<!----></p><!----></section></div></div></div></div>
<!-- built files will be auto injected -->
</div>
</main>
</div>
<!--googleoff: all-->
<div id="to-top"><a class="btn_slideto affix-top" href="#masthead" aria-label="Back to Top"><span class="web-icon-upload"></span></a></div>
<footer class="footer-main">
<div class="footer-top">
<div class="container">
<div class="brand">
<a href="https://redhat.com/">
<svg class="rh-logo" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 613 145">
<defs>
<style>
.rh-logo-hat {
fill: #e00;
}
.rh-logo-type {
fill: #fff;
}
</style>
</defs>
<title>Red Hat</title>
<path class="rh-logo-hat" d="M127.47,83.49c12.51,0,30.61-2.58,30.61-17.46a14,14,0,0,0-.31-3.42l-7.45-32.36c-1.72-7.12-3.23-10.35-15.73-16.6C124.89,8.69,103.76.5,97.51.5,91.69.5,90,8,83.06,8c-6.68,0-11.64-5.6-17.89-5.6-6,0-9.91,4.09-12.93,12.5,0,0-8.41,23.72-9.49,27.16A6.43,6.43,0,0,0,42.53,44c0,9.22,36.3,39.45,84.94,39.45M160,72.07c1.73,8.19,1.73,9.05,1.73,10.13,0,14-15.74,21.77-36.43,21.77C78.54,104,37.58,76.6,37.58,58.49a18.45,18.45,0,0,1,1.51-7.33C22.27,52,.5,55,.5,74.22c0,31.48,74.59,70.28,133.65,70.28,45.28,0,56.7-20.48,56.7-36.65,0-12.72-11-27.16-30.83-35.78"></path>
<path class="rh-logo-band" d="M160,72.07c1.73,8.19,1.73,9.05,1.73,10.13,0,14-15.74,21.77-36.43,21.77C78.54,104,37.58,76.6,37.58,58.49a18.45,18.45,0,0,1,1.51-7.33l3.66-9.06A6.43,6.43,0,0,0,42.53,44c0,9.22,36.3,39.45,84.94,39.45,12.51,0,30.61-2.58,30.61-17.46a14,14,0,0,0-.31-3.42Z"></path>
<path class="rh-logo-type" d="M579.74,92.8c0,11.89,7.15,17.67,20.19,17.67a52.11,52.11,0,0,0,11.89-1.68V95a24.84,24.84,0,0,1-7.68,1.16c-5.37,0-7.36-1.68-7.36-6.73V68.3h15.56V54.1H596.78v-18l-17,3.68V54.1H568.49V68.3h11.25Zm-53,.32c0-3.68,3.69-5.47,9.26-5.47a43.12,43.12,0,0,1,10.1,1.26v7.15a21.51,21.51,0,0,1-10.63,2.63c-5.46,0-8.73-2.1-8.73-5.57m5.2,17.56c6,0,10.84-1.26,15.36-4.31v3.37h16.82V74.08c0-13.56-9.14-21-24.39-21-8.52,0-16.94,2-26,6.1l6.1,12.52c6.52-2.74,12-4.42,16.83-4.42,7,0,10.62,2.73,10.62,8.31v2.73a49.53,49.53,0,0,0-12.62-1.58c-14.31,0-22.93,6-22.93,16.73,0,9.78,7.78,17.24,20.19,17.24m-92.44-.94h18.09V80.92h30.29v28.82H506V36.12H487.93V64.41H457.64V36.12H439.55ZM370.62,81.87c0-8,6.31-14.1,14.62-14.1A17.22,17.22,0,0,1,397,72.09V91.54A16.36,16.36,0,0,1,385.24,96c-8.2,0-14.62-6.1-14.62-14.09m26.61,27.87h16.83V32.44l-17,3.68V57.05a28.3,28.3,0,0,0-14.2-3.68c-16.19,0-28.92,12.51-28.92,28.5a28.25,28.25,0,0,0,28.4,28.6,25.12,25.12,0,0,0,14.93-4.83ZM320,67c5.36,0,9.88,3.47,11.67,8.83H308.47C310.15,70.3,314.36,67,320,67M291.33,82c0,16.2,13.25,28.82,30.28,28.82,9.36,0,16.2-2.53,23.25-8.42l-11.26-10c-2.63,2.74-6.52,4.21-11.14,4.21a14.39,14.39,0,0,1-13.68-8.83h39.65V83.55c0-17.67-11.88-30.39-28.08-30.39a28.57,28.57,0,0,0-29,28.81M262,51.58c6,0,9.36,3.78,9.36,8.31S268,68.2,262,68.2H244.11V51.58Zm-36,58.16h18.09V82.92h13.77l13.89,26.82H292l-16.2-29.45a22.27,22.27,0,0,0,13.88-20.72c0-13.25-10.41-23.45-26-23.45H226Z"></path>
</svg>
</a>
</div>
<div role="navigation">
<h3>Quick Links</h3>
<ul>
<li><a class="download-software" href="https://access.redhat.com/downloads/">Downloads</a></li>
<li><a class="manage-subscriptions" href="https://access.redhat.com/management/subscriptions/#active">Subscriptions</a></li>
<li><a class="support-cases" href="https://access.redhat.com/support">Support Cases</a></li>
<li><a class="customer-service" href="https://access.redhat.com/support/customer-service">Customer Service</a></li>
<li><a class="quick-docs" href="https://access.redhat.com/documentation">Product Documentation</a></li>
</ul>
</div>
<div role="navigation">
<h3>Help</h3>
<ul>
<li><a class="contact-us" href="https://access.redhat.com/support/contact/">Contact Us</a></li>
<li><a class="cp-faqs" href="https://access.redhat.com/articles/33844">Customer Portal FAQ</a></li>
<li><a class="login-problems" href="https://access.redhat.com/help/login_assistance">Log-in Assistance</a></li>
</ul>
</div>
<div role="navigation">
<h3>Site Info</h3>
<ul>
<li><a class="trust-red-hat" href="https://www.redhat.com/en/trust">Trust Red Hat</a></li>
<li><a class="browser-support-policy" href="https://access.redhat.com/help/browsers/">Browser Support Policy</a></li>
<li><a class="accessibility" href="https://access.redhat.com/help/accessibility/">Accessibility</a></li>
<li><a class="recognition" href="https://access.redhat.com/recognition/">Awards and Recognition</a></li>
<li><a class="colophon" href="https://access.redhat.com/help/colophon/">Colophon</a></li>
</ul>
</div>
<div role="navigation">
<h3>Related Sites</h3>
<ul>
<li><a href="https://www.redhat.com/" class="red-hat-com">redhat.com</a></li>
<li><a href="https://www.openshift.com/" class="openshift-com">openshift.com</a></li>
<li><a href="http://developers.redhat.com/" class="red-hat-developers">developers.redhat.com</a></li>
<li><a href="https://connect.redhat.com/" class="partner-connect">connect.redhat.com</a></li>
</ul>
</div>
<div role="navigation">
<h3>About</h3>
<ul>
<li><a href="https://access.redhat.com/subscription-value" class="subscription-value">Red Hat Subscription Value</a></li>
<li><a href="https://www.redhat.com/about/" class="about-red-hat">About Red Hat</a></li>
<li><a href="http://jobs.redhat.com/" class="about-jobs">Red Hat Jobs</a></li>
</ul>
</div>
</div>
</div>
<div class="anchor">
<div class="container">
<div class="status-legal">
<a href="https://status.redhat.com/" class="status-page-widget">
<span class="status-description">All systems operational</span>
<span class="status-dot shape-circle shape-dash-lime"></span>
</a>
<div class="legal-copyright">
<div class="copyright">Copyright © 2021 Red Hat, Inc.</div>
<div role="navigation" class="legal">
<ul>
<li><a href="http://www.redhat.com/en/about/privacy-policy" class="privacy-policy">Privacy Statement</a></li>
<li><a href="https://access.redhat.com/help/terms/" class="terms-of-use">Customer Portal Terms of Use</a></li>
<li><a href="http://www.redhat.com/en/about/all-policies-guidelines" class="all-policies">All Policies and Guidelines</a></li>
<li><a id="teconsent" consent="undefined" aria-label="Open Cookie Preferences Modal" role="complementary"><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/v1.7-193" async="async" crossorigin=""></script><a role="link" id="icon-id015658058456275448" tabindex="0" style="cursor: pointer;" lang="en">Cookie Preferences</a><script src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/notice_002" async="async" crossorigin=""></script></a></li>
</ul>
</div>
</div>
</div>
<div class="social">
<a href="http://www.redhat.com/summit/" class="summit">
<img src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/rh-summit-red-a.svg" alt="Red Hat Summit">
</a>
<div class="social-media">
<a href="https://twitter.com/RedHatSupport" class="sm-icon twitter"><span class="nicon-twitter"></span><span class="offscreen">Twitter</span></a>
<a href="https://www.facebook.com/RedHatSupport" class="sm-icon facebook"><span class="nicon-facebook"></span><span class="offscreen">Facebook</span></a>
</div>
</div>
</div>
</div>
</footer>
<!-- TrustArc -->
<div id="consent_blackbar"><style> @font-face{ font-family:"RedHatDisplayBold"; src: url(https://consent.trustarc.com/get?name=RedHatDisplay-Bold.ttf) format("truetype");}@font-face{ font-family:"RedHatDisplayMedium"; src: url(https://consent.trustarc.com/get?name=RedHatDisplay-Medium.ttf) format("truetype");}@font-face{ font-family:"RedHatTextRegular"; src: url(https://consent.trustarc.com/get?name=RedHatText-Regular.ttf) format("truetype");} #truste-consent-track{ background-color: #FFF; max-width: 412px; border-top: 2px solid #2B9AF3; box-shadow: 0px 5px 15px rgb(0 0 0 / 20%); position: fixed; bottom: 32px; left: 32px; right: 32px; } .truste-banner { margin: 0 auto; padding: 16px; } .truste-messageColumn { font-family: RedHatTextRegular; font-size: 14px; color: #000; margin: 0; line-height: 21px; padding: 0 0 0 32px; position: relative; } .truste-buttonsColumn { position: absolute; right: 16px; top: 11px; } .hidedesktop { display: none; font-family: RedHatTextRegular; font-size: 14px; cursor: pointer; color: #00559c; text-decoration:none; } .truste-cookie-link { font-family: RedHatTextRegular; cursor: pointer; color: #0066CC; text-decoration: none; } .truste-info-icon { width: 18px; position: absolute; left: 0; top: 1px;} span.truste-titlee { color: #002952; font-family: RedHatDisplayMedium; display: block; padding-bottom: 8px; font-weight: 600;}img.truste-info-icon { filter: invert(44%) sepia(82%) saturate(679%) hue-rotate(171deg) brightness(104%) contrast(91%);}button#truste-consent-button { background: none; border: none; cursor: pointer; padding: 0; margin: 0;}button#truste-consent-button img { filter: invert(45%) sepia(8%) saturate(284%) hue-rotate(173deg) brightness(92%) contrast(89%); width: 10px;} /* MEDIA QUERIES */ @media screen and (max-width: 768px){ #truste-consent-track{ max-width: 314px; left: 24px; right: 24px; bottom: 24px; } } @media screen and (max-width: 404px){ #truste-consent-track{ max-width: 100%; } } @media screen and (max-width: 420px) { .hidedesktop { display: inline; font-size: 14px; cursor: pointer; color: #00559c; text-decoration:none; } } @media screen and (min-width: 421px) and (max-width: 856px) { .hidedesktop { display: inline; font-size: 14px; cursor: pointer; color: #00559c; text-decoration:none; } } </style><div id="truste-consent-track" style="display: block; opacity: 1;"> <div id="truste-consent-content" class="truste-banner" style="overflow: hidden; max-width: 1200px; max-height:auto;"> <div id="truste-consent-text" class="truste-messageColumn"><img class="truste-info-icon" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/get.svg"><span class="truste-titlee">How we use cookies</span>We
use cookies on our websites to deliver our online services. Details
about how we use cookies and how you may disable them are set out in
our&nbsp;<a href="http://www.redhat.com/en/about/privacy-policy#cookies" target="_blank" class="truste-cookie-link">Privacy Statement</a>. By using this website you agree to our use of cookies. </div> <div id="truste-consent-buttons" class="truste-buttonsColumn"> <button id="truste-consent-button" type="button" class="truste-button1"><img alt="Close" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/get_002.svg"></button> </div> </div> </div></div>
<!--googleon: all-->
</div>
<script type="text/javascript" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/chunk-vendors.js"></script><script type="text/javascript" src="CVE-2019-14899-%20Red%20Hat%20Customer%20Portal_files/app.js"></script>
</body></html>