CVE-2018-25423: Arm Whois 3.11 Denial of Service via Buffer Overflow
Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input field to trigger a denial of service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Arm Whois 3.11from your environment.Uninstall Arm Whois 3.11 from systems where the application is not required to eliminate the vulnerable component.
- Compensating control
Prevent untrusted local users from interacting with the application: restrict interactive access to hosts running Arm Whois (use OS account permissions, local firewall rules, or host hardening), and run the application with least privilege to limit impact of a crash by a local attacker.
- Operational
Instruct users and administrators not to paste oversized input buffers into the IP address or domain input fields (the vulnerability is triggered by ~700-byte inputs). Monitor for application crashes, capture crash dumps/logs for investigation, and restart services as needed.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25423?
The severity of CVE-2018-25423 is rated as medium with a score of 6.2.
What type of vulnerability is CVE-2018-25423?
CVE-2018-25423 is a buffer overflow vulnerability that may lead to a denial of service.
How can CVE-2018-25423 be exploited?
CVE-2018-25423 can be exploited by local attackers supplying an oversized input string of 700 bytes in the IP address or domain input field.
How do I fix CVE-2018-25423?
To fix CVE-2018-25423, ensure you are using an updated version of Arm Whois that addresses the buffer overflow issue.
What impact does CVE-2018-25423 have on the application?
CVE-2018-25423 can cause Arm Whois 3.11 to crash, resulting in a denial of service condition.