CVE-2018-18439: Buffer Overflow
Published Nov 20, 2018
·Updated
DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image.
Affected Software
2 affected components
DENX U-Boot<2018.09
DENX U-Boot=2018.09-rc1
Event History
Nov 20, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18439?
The severity of CVE-2018-18439 is critical, with a CVSS score of 9.8.
2
What software is affected by CVE-2018-18439?
DENX U-Boot versions up to and including 2018.09-rc1 are affected by CVE-2018-18439.
3
How can CVE-2018-18439 be exploited remotely?
CVE-2018-18439 can be remotely exploited through a malicious TFTP server by mishandling TFTP traffic.
4
Can CVE-2018-18439 be exploited locally?
Yes, CVE-2018-18439 can be locally exploited with a crafted kernel image.
5
Is there a fix available for CVE-2018-18439?
Yes, updating to a version beyond 2018.09-rc1 of DENX U-Boot can fix the vulnerability.