CVE-2018-20034: High severity flexera flexnet publisher vulnerability
A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20034?
CVE-2018-20034 is a Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier.
How severe is CVE-2018-20034?
CVE-2018-20034 has a severity rating of 7.5 (high).
What software is affected by CVE-2018-20034?
Flexera Flexnet Publisher version 11.16.1.0 and earlier, as well as Oracle Communications Lsms version 13.1 to 13.4, are affected by CVE-2018-20034.
How can an attacker exploit CVE-2018-20034?
An attacker can exploit CVE-2018-20034 by sending a combination of messages to lmgrd or the vendor daemon, causing a denial of service by disrupting the heartbeat between lmgrd and the vendor.
Where can I find more information about CVE-2018-20034?
You can find more information about CVE-2018-20034 at the following references: SecurityFocus (http://www.securityfocus.com/bid/109155), Flexera Software (https://secuniaresearch.flexerasoftware.com/advisories/85979/), and Oracle Security Alerts (https://www.oracle.com/security-alerts/cpuoct2021.html).