Resource exhaustion in SEL AcSELerator Architect and SEL Compass - CVE-2018-10608

 

Resource exhaustion in SEL AcSELerator Architect and SEL Compass - CVE-2018-10608

Published: July 11, 2018


Vulnerability identifier: #VU13802
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10608
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to resource exhaustion when the AcSELerator Architect FTP client connects to a malicious FTP server. A remote attacker can consume memory and cause the service to crash.


Affected software

SEL AcSELerator Architect
SEL Compass
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse

How to mitigate CVE-2018-10608

Update SEL Compass to version 5.0.6.0 or later.
Update SEL AcSELerator  to version 2.2.28.0.


SEL AcSELerator Architect - update to 2.2.28.0
SEL Compass - update to 5.0.6.0

External References

Related Security Bulletins