CVE-2018-25033: High severity admesh vulnerability
Published May 8, 2022
·Updated
ADMesh through 0.98.4 has a heap-based buffer over-read in stlupdateconnectsremove1 (called from stlremovedegenerate) in connect.c in libadmesh.a.
Affected Software
2 affected components
Admesh Project Admesh<=0.98.4
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
May 8, 2022
CVE Published
via MITRE·05:03 AM
Data Sourced
via MITRE·05:03 AM
Description
Frequently Asked Questions
1
What is CVE-2018-25033?
CVE-2018-25033 is a vulnerability in ADMesh software through version 0.98.4 that allows a heap-based buffer over-read.
2
How does CVE-2018-25033 affect software?
CVE-2018-25033 affects ADMesh software version 0.98.4 and Debian Linux version 9.0.
3
What is the severity of CVE-2018-25033?
CVE-2018-25033 has a severity rating of 8.1 (high).
4
How can I fix CVE-2018-25033?
To fix CVE-2018-25033, update ADMesh software to a version beyond 0.98.4.
5
Where can I find more information about CVE-2018-25033?
More information about CVE-2018-25033 can be found in the references: [link1](https://github.com/admesh/admesh/issues/28), [link2](https://lists.debian.org/debian-lts-announce/2022/05/msg00029.html).