Out-of-bounds read in Debian Linux - CVE-2018-7436
Published: February 23, 2018 / Updated: August 8, 2020
Vulnerability identifier: #VU37500
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7436
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read in a pointer dereference of the parse_SST function. A remote attacker can perform a denial of service attack.
Affected software
Debian Linux
Gentoo Linux
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
Gentoo Linux
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2018-7436
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.