CVE-2018-6331: Critical severity facebook buck vulnerability
Published Dec 31, 2018
·Updated
Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01.
Affected Software
1 affected component
Facebook Buck<2018.06.25.01
Remediation
Event History
Dec 31, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Data Sourced
via NVD·11:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6331?
CVE-2018-6331 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2018-6331?
To fix CVE-2018-6331, upgrade Buck to version 2018.06.25.01 or later.
3
What software is affected by CVE-2018-6331?
CVE-2018-6331 affects all versions of Buck prior to 2018.06.25.01.
4
What is the exploit mechanism for CVE-2018-6331?
CVE-2018-6331 can be exploited by crafting malicious serialized objects that, when deserialized, lead to arbitrary code execution.
5
Who is the vendor responsible for CVE-2018-6331?
The vendor responsible for CVE-2018-6331 is Facebook, the creator of the Buck build system.