CVE-2018-5189: Buffer Overflow
Published Jan 11, 2018
·Updated
Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain system privileges by flipping pool buffer size, aka a "double fetch" vulnerability.
Affected Software
1 affected component
Jungo Windriver<12.6.0
Event History
Jan 11, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5189?
CVE-2018-5189 is considered a critical vulnerability due to its potential to allow local users to escalate privileges or cause a denial of service.
2
What causes the CVE-2018-5189 vulnerability?
CVE-2018-5189 is caused by a race condition that occurs when the pool buffer size is manipulated.
3
How do I fix CVE-2018-5189?
To fix CVE-2018-5189, upgrade Jungo Windriver to version 12.6.0 or later.
4
Who is affected by CVE-2018-5189?
CVE-2018-5189 affects local users of Jungo Windriver version prior to 12.6.0.
5
What type of attack is enabled by CVE-2018-5189?
CVE-2018-5189 enables attacks that may lead to denial of service or privilege escalation.