CVE-2018-7485: Buffer Overflow
Published Feb 26, 2018
·Updated
The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.
Affected Software
2 affected componentsFixes available
redhat/unixODBC<2.3.6
2.3.6
unixODBC unixODBC=2.3.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/unixODBCto a version that resolves this vulnerability.Fixed in 2.3.6
Event History
Feb 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-7485.
2
What is the severity of CVE-2018-7485?
The severity of CVE-2018-7485 is critical with a CVSS score of 9.8.
3
What is the affected software of CVE-2018-7485?
The affected software of CVE-2018-7485 is unixODBC version 2.3.5.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers to cause a denial of service or have unspecified other impact.
5
How can I fix CVE-2018-7485?
To fix CVE-2018-7485, upgrade to unixODBC version 2.3.6 or later.