CVE-2018-18409: Medium severity Digitalcorpora Tcpflow vulnerability
Published Oct 17, 2018
·Updated
A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an addresshistogram call or a gethistogram call.
Affected Software
7 affected componentsFixes available
Digitalcorpora Tcpflow=1.5.0
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
debian/tcpflow
1.5.2+repack1-11.5.2+repack1-1+deb11u11.6.1-21.6.1-3
Remediation
Patch Available
Event History
Oct 17, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·05:12 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·05:13 PM
Description
Data Sourced
via Debian·05:13 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-18409?
The severity of CVE-2018-18409 is classified as moderate due to the potential for denial of service.
2
How do I fix CVE-2018-18409?
To fix CVE-2018-18409, upgrade to tcpflow version 1.5.2+repack1-1 or higher.
3
What are the affected software versions for CVE-2018-18409?
CVE-2018-18409 affects tcpflow version 1.5.0; versions 1.5.2 and later are not vulnerable.
4
What type of vulnerability is CVE-2018-18409?
CVE-2018-18409 is a stack-based buffer over-read vulnerability.
5
In what functions does CVE-2018-18409 manifest?
CVE-2018-18409 occurs in the setbit() function within iptree.h during address_histogram or get_histogram calls.