CVE-2018-20336: Buffer Overflow
Published Sep 17, 2019
·Updated
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parsereqqueries function in wanduck.c via a long string over UDP, which may lead to an information leak.
Affected Software
2 affected components
ASUS Asuswrt-merlin=3.0.0.4.384.20308
ASUS RT-AC68U
Event History
Sep 17, 2019
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20336?
The severity of CVE-2018-20336 is high with a score of 7.5.
2
What is the affected software of CVE-2018-20336?
The affected software of CVE-2018-20336 is Asus Asuswrt-merlin 3.0.0.4.384.20308.
3
How can the vulnerability in CVE-2018-20336 be exploited?
The vulnerability in CVE-2018-20336 can be exploited by sending a long string over UDP to trigger a stack-based buffer overflow in the parse_req_queries function in wanduck.c.
4
What is the Common Weakness Enumeration (CWE) ID of CVE-2018-20336?
The Common Weakness Enumeration (CWE) ID of CVE-2018-20336 is CWE-119 and CWE-120.
5
How can I fix CVE-2018-20336?
To fix CVE-2018-20336, update the affected software to a version that includes a patch for the vulnerability.