CVE-2018-18408: Use After Free
Published Oct 17, 2018
·Updated
A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function postargs() at tcpbridge.c, causing a denial of service or possibly unspecified other impact.
Affected Software
3 affected components
Broadcom Tcpreplay=4.3.0-beta1
fedoraproject fedora=28
fedoraproject fedora=29
Remediation
Patch Available
Event History
Oct 17, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-18408.
2
What is the severity of CVE-2018-18408?
The severity of CVE-2018-18408 is critical.
3
What software is affected by CVE-2018-18408?
Broadcom Tcpreplay version 4.3.0 beta1, Fedoraproject Fedora versions 28 and 29 are affected by CVE-2018-18408.
4
How can CVE-2018-18408 be exploited?
CVE-2018-18408 can be exploited by triggering the use-after-free issue in the post_args() function of the tcpbridge binary in Tcpreplay.
5
Are there any known fixes or mitigation measures for CVE-2018-18408?
Updates and patches are available from the software vendors to fix CVE-2018-18408. It is recommended to update to a patched version or apply the necessary security fixes as soon as possible.