Vulnerabilities > CVE-2018-17942 - Out-of-bounds Write vulnerability in GNU Gnulib

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
gnu
CWE-787
nessus

Summary

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.

Vulnerable Configurations

Part Description Count
Application
Gnu
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-3A25355AB6.NASL
    description - fix heap-based buffer overflow in vasnprintf() (CVE-2018-17942) Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2019-01-03
    plugin id120359
    published2019-01-03
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/120359
    titleFedora 29 : coreutils (2018-3a25355ab6)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2020-ACAC61CFD0.NASL
    descriptionSecurity fix for [CVE-2018-17942] - Update on 2020-01-07 - CVE-2018-17942 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id133015
    published2020-01-17
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/133015
    titleFedora 30 : gnulib (2020-acac61cfd0)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2020-663F619E9C.NASL
    descriptionSecurity fix for [CVE-2018-17942] - Update on 2020-01-07 - CVE-2018-17942 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id133012
    published2020-01-17
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/133012
    titleFedora 31 : gnulib (2020-663f619e9c)