Input validation error in Floating License Manager - CVE-2018-20031
Published: July 12, 2019
Floating License Manager
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input related to preemptive item deletion in lmadmin and vendor daemon components. A remote attacker can send a combination of messages to lmadmin or the vendor daemon, causing the heartbeat between lmadmin and the vendor daemon to stop and the vendor daemon to shut down.