CVE-2018-1000046: High severity nasa pyblock vulnerability
Published Feb 9, 2018
·Updated
NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability appears to have been fixed in v1.4.
Affected Software
1 affected component
nasa Pyblock>=1.0<=1.3
Remediation
Patch Available
Event History
Feb 9, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-1000046?
CVE-2018-1000046 is a vulnerability in NASA Pyblock version v1.0 - v1.3 that can result in remote code execution.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by opening a specially crafted radar data file.
3
Which version of NASA Pyblock is affected by this vulnerability?
NASA Pyblock versions v1.0 - v1.3 are affected by this vulnerability.
4
Has this vulnerability been fixed?
Yes, this vulnerability has been fixed in NASA Pyblock version v1.4.
5
What is the severity of CVE-2018-1000046?
CVE-2018-1000046 has a severity rating of 7.8 (high).