CVE-2018-5282: Buffer Overflow
DISPUTED Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor disputes this issue because neither a buffer overflow nor a crash can be reproduced; also, reading XML documents is implemented exclusively with managed code within the Microsoft .NET Framework.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5282?
The CVE-2018-5282 vulnerability has a disputed severity classification as the vendor claims no exploits have been successfully reproduced.
How do I fix CVE-2018-5282?
To address CVE-2018-5282, consider updating Kentico CMS to a version beyond 11.0 and review security practices regarding XML document handling.
Which versions of Kentico are affected by CVE-2018-5282?
CVE-2018-5282 affects Kentico CMS versions 9.0 through 11.0.
Is CVE-2018-5282 a confirmed vulnerability?
CVE-2018-5282 is a disputed vulnerability as the vendor contends that neither a buffer overflow nor a crash can be reproduced.
What fields are involved in CVE-2018-5282?
CVE-2018-5282 relates to a stack-based buffer overflow in the SqlName, SqlPswd, Database, UserName, and Password fields within a SilentInstall XML document.