CVE-2018-18385
Last modified
CVE-2018-18385 is a vulnerability of currently unknown severity. Asciidoctor in versions < 1.5.8 allows remote attackers to cause a denial of service (infinite loop). The loop was caused by the fact that Parser.next_block was not exhausting all the lines in the reader as the while loop expected it would. EPSS estimates a 2.25% chance of exploitation in the next 30 days.
Description
Asciidoctor in versions < 1.5.8 allows remote attackers to cause a denial of service (infinite loop). The loop was caused by the fact that Parser.next_block was not exhausting all the lines in the reader as the while loop expected it would. This was happening because the regular expression that detects any list was not agreeing with the regular expression that detects a specific list type. So the line kept getting pushed back onto the reader, hence causing the loop.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Asciidoctor | Asciidoctor | < 1.5.8 |
References
- https://github.com/asciidoctor/asciidoctor/issues/2888Exploit, Third Party Advisory
- https://github.com/asciidoctor/asciidoctor/issues/2888Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18385?
How severe is CVE-2018-18385?
How do I fix CVE-2018-18385?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18379The elementor-edit-template class in wp-admin/customize.php …6.1
- CVE-2018-1838IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud co…5.3
- CVE-2018-18380A Session Fixation issue was discovered in Bigtree before 4.…
- CVE-2018-18381Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability i…5.4
- CVE-2018-18382Advanced HRM 1.6 allows Remote Code Execution via PHP code i…
- CVE-2018-18384Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a Z…
- CVE-2018-18386drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allow…
- CVE-2018-18387playSMS through 1.4.2 allows Privilege Escalation through Da…
- CVE-2018-18388eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld…
- CVE-2018-18389Due to incorrect access control in Neo4j Enterprise Database…
- CVE-2018-18390User Enumeration in Moxa ThingsPro IIoT Gateway and Device M…
- CVE-2018-18391User Privilege Escalation in Moxa ThingsPro IIoT Gateway and…
Are you affected by CVE-2018-18385?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
