CVE-2018-11768: Buffer Overflow
In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability CVE-2018-11768?
The vulnerability CVE-2018-11768 is a user/group information corruption vulnerability in Apache Hadoop.
What software versions are affected by CVE-2018-11768?
The software versions affected by CVE-2018-11768 include Apache Hadoop 2.2.0 to 2.8.4, 2.9.0 to 2.9.1, 3.0.1 to 3.0.3, and 3.1.0 to 3.1.1.
What is the severity of CVE-2018-11768?
CVE-2018-11768 has a severity rating of 7.5 (high).
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-11768?
The Common Weakness Enumeration (CWE) ID for CVE-2018-11768 is 119.
Are there any references available for CVE-2018-11768?
Yes, you can find references for CVE-2018-11768 at the following links: [Link 1](https://lists.apache.org/thread.html/2067a797b330530a6932f4b08f703b3173253d0a2b7c8c524e54adaf@%3Cgeneral.hadoop.apache.org%3E), [Link 2](https://lists.apache.org/thread.html/2c9cc65864be0058a5d5ed2025dfb9c700bf23d352b0c826c36ff96a@%3Chdfs-dev.hadoop.apache.org%3E), [Link 3](https://lists.apache.org/thread.html/72ca514e01cd5f08151e74f9929799b4cbe1b6e9e6cd24faa72ffcc6@%3Cdev.lucene.apache.org%3E).