Uncontrolled memory allocation in Guava: Google Core Libraries For Java - CVE-2018-10237

 

Uncontrolled memory allocation in Guava: Google Core Libraries For Java - CVE-2018-10237

Published: May 21, 2018 / Updated: May 23, 2018


Vulnerability identifier: #VU12886
CSH Severity: Low
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-10237
CWE-ID: CWE-789
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to unbounded memory allocation. A remote attacker can cause the service to crash and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

Affected software

Guava: Google Core Libraries For Java
IBM Business Automation Workflow
IBM Integration Bus
IBM PureData System for Operational Analytics
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
Red Hat OpenStack for IBM Power
Red Hat OpenStack
IBM Observability with Instana
Financial Transaction Manager for ACH Services and Check Services
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
IBM Security Verify Governance
IBM Spectrum Protect Plus
IBM Tivoli Application Dependency Discovery Manager
Cloudera Data Platform Private Cloud Base for IBM
Apache Pulsar
Voice Gateway
Red Hat OpenShift Container Platform
DataStage on Cloud Pak for Data
IBM OpenPages with Watson
Oracle Retail Xstore Point of Service
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
User Entity Behavior Analytics
Synthetic Playback Agent
Storage Virtualize
Maximo Application Suite - IoT Component
IBM Sterling Order Management
JBoss Enterprise Application Platform
Oracle WebLogic Server
Splunk Enterprise
IBM Security Guardium
Fedora
watsonx.data
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Case Manager
RSA Authentication Manager
Operational Decision Manager
IBM App Connect Enterprise
IBM InfoSphere Information Server
guava
guava20

How to mitigate CVE-2018-10237

Update to version 24.1.1.

Apache Pulsar - update to 2.8.0
IBM Process Mining - update to 2.1.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM OpenPages with Watson - update to 8.2.0.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.0.9, 9.1.1, 9.1.4, 9.2.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Observability with Instana - update to 1.0.295
watsonx.data - update to 2.0.3
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
User Entity Behavior Analytics - update to 5.0.2
IBM Case Manager - update to 5.3.3-IF011
Synthetic Playback Agent - update to 8.1.4 IF18
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Spectrum Protect Storage Agent - update to 8.1.19
RSA Authentication Manager - update to 8.5 Patch 3
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.15, 8.8.11, 9.0.1
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM Sterling Order Management - update to 10.0.0.29
IBM Security Verify Governance - update to 10.0.1.0.4
IBM Spectrum Protect Plus - update to 10.1.14
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 12.0.9.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
guava - addressed in versions 18.0-12.fc26, 18.0-12.fc27, 24.0-3.fc28
guava20 - update to 20.0-6.fc28

External References

Related Security Bulletins