CVE-2018-6758: Buffer Overflow
Published Feb 6, 2018
·Updated
The uwsgiexpandpath function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a large directory length.
Affected Software
2 affected componentsFixes available
debian/uwsgi
2.0.18-12.0.19.1-7.12.0.21-5.12.0.22-4
Unbit uwsgi<=2.0.15
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/uwsgito a version that resolves this vulnerability.Fixed in 2.0.18-1Fixed in 2.0.19.1-7.1Fixed in 2.0.21-5.1Fixed in 2.0.22-4
Event History
Feb 6, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-6758.
2
What is the severity of CVE-2018-6758?
The severity of CVE-2018-6758 is critical, with a CVSS score of 9.8.
3
How does CVE-2018-6758 affect Unbit uWSGI?
CVE-2018-6758 affects Unbit uWSGI versions up to 2.0.15.
4
How can I fix CVE-2018-6758?
To fix CVE-2018-6758, update Unbit uWSGI to versions 2.0.18-1, 2.0.19.1-7.1, 2.0.21-5.1, or 2.0.22-4.
5
Where can I find more information about CVE-2018-6758?
More information about CVE-2018-6758 can be found in the following references: [1] [2] [3].