Out-of-bounds read in Debian Linux - CVE-2018-7438
Published: February 23, 2018 / Updated: August 8, 2020
Vulnerability identifier: #VU37502
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7438
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read in the parse_unicode_string function. A remote attacker can perform a denial of service attack.
Affected software
Debian Linux
Gentoo Linux
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
Gentoo Linux
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2018-7438
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.