CVE-2018-6918: High severity Apple AirPort Base Station Firmware Update vulnerability
AirPort Base Station Firmware. A denial of service issue was addressed with improved validation.
Other sources
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote attacker who is able to send an arbitrary packet to cause the machine to crash.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple AirPort Base Station Firmware Updateto a version that resolves this vulnerability.Fixed in 7.9.1 - Upgrade
Upgrade
Apple AirPort Base Station Firmware Updateto a version that resolves this vulnerability.Fixed in 7.8.1 - Upgrade
Upgrade
FreeBSDto a version that resolves this vulnerability.Fixed in 11.1-STABLE - Upgrade
Upgrade
FreeBSDto a version that resolves this vulnerability.Fixed in 11.1-RELEASE-p9 - Upgrade
Upgrade
FreeBSDto a version that resolves this vulnerability.Fixed in 10.4-STABLE - Upgrade
Upgrade
FreeBSDto a version that resolves this vulnerability.Fixed in 10.4-RELEASE-p8 - Upgrade
Upgrade
FreeBSDto a version that resolves this vulnerability.Fixed in 10.3-RELEASE-p28
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-6918?
CVE-2018-6918 is a denial of service vulnerability that can disrupt the functioning of affected devices.
How do I fix CVE-2018-6918?
To fix CVE-2018-6918, update the AirPort Base Station Firmware to version 7.9.1 or 7.8.1 or ensure your FreeBSD version is updated to the necessary secure releases.
Which devices are affected by CVE-2018-6918?
CVE-2018-6918 affects Apple AirPort Base Station Firmware as well as certain versions of FreeBSD prior to 11.1 and 10.4.
What symptoms indicate an attack related to CVE-2018-6918?
Symptoms of an attack exploiting CVE-2018-6918 may include unexpected downtime or unresponsiveness of the network services on affected devices.
Is there a workaround for CVE-2018-6918?
There are no specific workarounds for CVE-2018-6918; upgrading to the patched firmware is required to mitigate the vulnerability.