CVE-2018-25367: NASA openVSP 3.16.1 Denial of Service via Buffer Overflow
NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25367?
The severity of CVE-2018-25367 is medium with a score of 6.2.
How do I fix CVE-2018-25367?
To fix CVE-2018-25367, users should update to a patched version of NASA openVSP that addresses the buffer overflow vulnerability.
What type of vulnerability is CVE-2018-25367?
CVE-2018-25367 is a buffer overflow vulnerability that can lead to a denial of service.
Who is affected by CVE-2018-25367?
CVE-2018-25367 affects users of NASA openVSP version 3.16.1.
What impact does CVE-2018-25367 have on systems?
CVE-2018-25367 allows local attackers to crash the NASA openVSP application, resulting in a denial of service.