Buffer overflow in Hadoop - CVE-2018-11768

 

Buffer overflow in Hadoop - CVE-2018-11768

Published: October 4, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35193
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11768
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.


Affected software

Hadoop
IBM Qradar SIEM
watsonx.data
IBM Cloud Application Performance Management (APM)

How to mitigate CVE-2018-11768

Install update from vendor's website.

IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
watsonx.data - update to 2.0.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14

External References

Related Security Bulletins