First published: Thu Apr 26 2018(Updated: )
Google Guava is vulnerable to a denial of service, caused by improper eager allocation checks in the AtomicDoubleArray and CompoundOrdering class. By sending a specially-crafted data, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.google.guava:guava | >=11.0<24.1.1-android | 24.1.1-android |
maven/org.sonatype.sisu:sisu-guava | =0.11.1 | |
maven/org.hudsonci.lib.guava:guava | <=14.0.1-h-3 | |
maven/de.mhus.ports:vaadin-shared-deps | <=7.4.0 | |
maven/com.googlecode.guava-osgi:guava-osgi | <=11.0.1 | |
maven/com.google.guava:guava-jdk5 | <=17.0 | |
redhat/guava | <24.1.1 | 24.1.1 |
redhat/guava | <25.0 | 25.0 |
IBM GDE | <=3.0.0.2 | |
Google Guava | >=11.0<24.1.1 | |
redhat openshift container platform | =3.11 | |
redhat openstack | =13 | |
redhat satellite | =6.4 | |
Red Hat Satellite Capsule | =6.4 | |
Red Hat Enterprise Virtualization | =4.2 | |
redhat virtualization host | =4.0 | |
redhat jboss enterprise application platform | =6.0.0 | |
redhat jboss enterprise application platform | =6.4.0 | |
redhat jboss enterprise application platform | =7.1.0 | |
redhat openshift container platform | =4.1 | |
Red Hat Enterprise Virtualization | =4.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =5.0 | |
Red Hat Enterprise Linux | =6.0 | |
Oracle Banking Payments | >=14.1.0<=14.4.0 | |
Oracle Communications IP Service Activator | =7.3.0 | |
Oracle Communications IP Service Activator | =7.4.0 | |
Oracle Customer Management and Segmentation Foundation | =18.0 | |
Oracle Database | =12.2.0.1 | |
Oracle Database | =18c | |
Oracle Database | =19c | |
Oracle FLEXCUBE Investor Servicing | =12.1.0 | |
Oracle FLEXCUBE Investor Servicing | =12.3.0 | |
Oracle FLEXCUBE Investor Servicing | =12.4.0 | |
Oracle FLEXCUBE Investor Servicing | =14.0.0 | |
Oracle FLEXCUBE Investor Servicing | =14.1.0 | |
Oracle FLEXCUBE Private Banking | =12.0.0 | |
Oracle FLEXCUBE Private Banking | =12.1.0 | |
Oracle Retail Integration Bus | =15.0 | |
Oracle Retail Integration Bus | =16.0 | |
Oracle Retail Xstore Office Cloud Service | =7.1 | |
Oracle Retail Xstore Office Cloud Service | =15.0 | |
Oracle Retail Xstore Office Cloud Service | =16.0 | |
Oracle Retail Xstore Office Cloud Service | =17.0 | |
Oracle WebLogic Server | =12.2.1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10237 has a severity rating indicating it can lead to denial of service conditions.
To fix CVE-2018-10237, users should upgrade to Google Guava version 24.1.1 or later.
Google Guava versions from 11.0 to 24.1.1 are affected by CVE-2018-10237.
Currently, the recommended solution for CVE-2018-10237 is to upgrade to a patched version rather than relying on workarounds.
CVE-2018-10237 allows attackers to cause a denial of service by sending specially-crafted data.