PT-2018-3582 · Linux+3 · Blktrace+3
Herbo Zhang
·
Published
2018-05-02
·
Updated
2021-07-08
·
CVE-2018-10689
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
blktrace versions 1.2.0
Description
The issue is related to a buffer overflow in the
dev map read function in btt/devmap.c due to the device and devno arrays being too small. This can be demonstrated by an invalid free when using the btt program with a crafted file. The exploitation of this issue may allow a remote attacker to cause a denial of service.Recommendations
For version 1.2.0, consider disabling the
dev map read function in btt/devmap.c as a temporary workaround until a patch is available. Restrict access to the btt program to minimize the risk of exploitation. Avoid using the btt program with crafted files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Blktrace