CVE-2018-18409

A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.
Configurations

Configuration 1 (hide)

cpe:2.3:a:digitalcorpora:tcpflow:1.5.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

History

21 Nov 2024, 03:55

Type Values Removed Values Added
References () https://github.com/simsong/tcpflow/issues/195 - Exploit, Patch, Third Party Advisory () https://github.com/simsong/tcpflow/issues/195 - Exploit, Patch, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K6MP4YMCJX4ITOBFX427UMOA6E7ZLJDE/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K6MP4YMCJX4ITOBFX427UMOA6E7ZLJDE/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MN5FW6HKPDP7PI2IVNMFSQVIDSCQ5BOR/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MN5FW6HKPDP7PI2IVNMFSQVIDSCQ5BOR/ -
References () https://usn.ubuntu.com/3955-1/ - Third Party Advisory () https://usn.ubuntu.com/3955-1/ - Third Party Advisory

Information

Published : 2018-10-17 04:29

Updated : 2024-11-21 03:55


NVD link : CVE-2018-18409

Mitre link : CVE-2018-18409

CVE.ORG link : CVE-2018-18409


JSON object : View

Products Affected

fedoraproject

  • fedora

digitalcorpora

  • tcpflow

canonical

  • ubuntu_linux
CWE
CWE-125

Out-of-bounds Read