Resource exhaustion in SEL AcSELerator Architect and SEL Compass - CVE-2018-10608
Published: July 11, 2018
Vulnerability identifier: #VU13802
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10608
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to resource exhaustion when the AcSELerator Architect FTP client connects to a malicious FTP server. A remote attacker can consume memory and cause the service to crash.
Affected software
SEL AcSELerator Architect
SEL Compass
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
SEL Compass
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
How to mitigate CVE-2018-10608
Update SEL Compass to version 5.0.6.0 or later.
Update SEL AcSELerator to version 2.2.28.0.
SEL AcSELerator Architect - update to 2.2.28.0
SEL Compass - update to 5.0.6.0
SEL Compass - update to 5.0.6.0