CVE-2018-6918
Last modified
CVE-2018-6918 is a vulnerability of currently unknown severity. In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote attacker who is able to send an arbitrary packet to cause the machine to crash.. EPSS estimates a 4.38% chance of exploitation in the next 30 days.
Description
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote attacker who is able to send an arbitrary packet to cause the machine to crash.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | >= 10.0, < 10.4 |
| Freebsd | Freebsd | >= 11.0, < 11.1 |
References
- http://www.securityfocus.com/bid/103666Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040628Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103666Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040628Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6918?
How severe is CVE-2018-6918?
How do I fix CVE-2018-6918?
Are you affected by CVE-2018-6918?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
