First published: Thu Oct 04 2018(Updated: )
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ranger | <1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11778 has a medium severity due to its potential to cause a stack-based buffer overflow.
To fix CVE-2018-11778, upgrade your Apache Ranger installation to version 1.2.0 or later.
CVE-2018-11778 affects Apache Ranger versions prior to 1.2.0.
CVE-2018-11778 addresses a vulnerability in the UnixAuthenticationService in Apache Ranger that could lead to a stack-based buffer overflow.
No, CVE-2018-11778 is not a zero-day vulnerability as it has a public disclosure and a patch is available.