CVE-2018-25021: High severity toktok toxcore vulnerability
Published Dec 13, 2021
·Updated
The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).
Affected Software
1 affected component
Toktok Toxcore<0.2.8
Event History
Dec 13, 2021
CVE Published
via MITRE·12:53 AM
Data Sourced
via MITRE·12:53 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-25021?
CVE-2018-25021 has a medium severity rating due to the potential for denial of service attacks.
2
How do I fix CVE-2018-25021?
To fix CVE-2018-25021, update your Toxcore to version 0.2.8 or later.
3
What type of attack is CVE-2018-25021 associated with?
CVE-2018-25021 is associated with a denial of service (DoS) attack due to memory exhaustion.
4
Which software versions are affected by CVE-2018-25021?
Toxcore versions prior to 0.2.8 are affected by CVE-2018-25021.
5
Can CVE-2018-25021 be exploited remotely?
Yes, CVE-2018-25021 can be exploited by a remote attacker to exhaust system memory.