CVE-2018-21232: Medium severity re2c vulnerability
Published Apr 29, 2020
·Updated
re2c before 2.0 has uncontrolled recursion that causes stack consumption in findfixedtags.
Affected Software
1 affected component
re2c re2c<2.0
Remediation
Patch Available
Event History
Apr 29, 2020
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21232?
CVE-2018-21232 is considered a high severity vulnerability due to its potential for causing denial of service through stack exhaustion.
2
How do I fix CVE-2018-21232?
To fix CVE-2018-21232, update to re2c version 2.0 or later, which addresses the uncontrolled recursion issue.
3
What software is affected by CVE-2018-21232?
CVE-2018-21232 affects re2c versions prior to 2.0.
4
What types of attacks can exploit CVE-2018-21232?
CVE-2018-21232 can be exploited through crafted input that triggers the uncontrolled recursion, leading to stack consumption.
5
Is CVE-2018-21232 still a risk if I have version 2.0 or later?
No, if you are using re2c version 2.0 or later, you are not at risk from CVE-2018-21232.