PT-2018-3582 · Linux+3 · Blktrace+3

Herbo Zhang

·

Publicado

2018-05-02

·

Atualizado

2021-07-08

·

CVE-2018-10689

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions blktrace versions 1.2.0
Description The issue is related to a buffer overflow in the dev map read function in btt/devmap.c due to the device and devno arrays being too small. This can be demonstrated by an invalid free when using the btt program with a crafted file. The exploitation of this issue may allow a remote attacker to cause a denial of service.
Recommendations For version 1.2.0, consider disabling the dev map read function in btt/devmap.c as a temporary workaround until a patch is available. Restrict access to the btt program to minimize the risk of exploitation. Avoid using the btt program with crafted files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-6328
BDU:2021-00237
CESA-2019_2162
CVE-2018-10689
OPENSUSE-SU-2019:1224-1
OPENSUSE-SU-2019_1224-1
RHSA-2019:2162
RHSA-2019_2162
SUSE-SU-2019:0919-1
SUSE-SU-2019_0919-1
SUSE-SU-2020:2942-1

Produtos afetados

Centos
Red Hat
Suse
Blktrace