CVE-2018-0493: Use After Free
Published Apr 3, 2018
·Updated
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.
Affected Software
3 affected componentsFixes available
debian/remctl
3.15-13.17-13.18-1
Eyrie Remctl<3.14
Debian Debian Linux=9.0
Event History
Apr 3, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0493?
CVE-2018-0493 has a high severity due to the potential for memory corruption and arbitrary command execution.
2
How do I fix CVE-2018-0493?
To fix CVE-2018-0493, upgrade to remctl version 3.15-1 or later.
3
What causes the vulnerability CVE-2018-0493?
CVE-2018-0493 is caused by a use-after-free condition in remctld when executing commands with the sudo option.
4
Which versions of remctl are affected by CVE-2018-0493?
CVE-2018-0493 affects remctl versions prior to 3.15.
5
What are the potential consequences of CVE-2018-0493 exploitation?
Exploitation of CVE-2018-0493 could lead to a daemon crash and the execution of arbitrary commands on the affected system.