CVE-2018-0004
published 2018-01-10CVE-2018-0004: A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and…
PriorityP432medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.25%
65.9th percentile
A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsystem when a specific command is issued to the device. This affects one or more threads and conversely one or more running processes running on the system. Once this occurs, the high CPU event(s) affects either or both the forwarding and control plane. As a result of this condition the device can become inaccessible in either or both the control and forwarding plane and stops forwarding traffic until the device is rebooted. The issue will reoccur after reboot upon receiving further transit traffic. Score: 5.7 MEDIUM (CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) For network designs utilizing layer 3 forwarding agents or other ARP through layer 3 technologies, the score is slightly higher. Score: 6.5 MEDIUM (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) If the following entry exists in the RE message logs then this may indicate the issue is present. This entry may or may not appear when this issue occurs. /kernel: Expensive timeout(9) function: Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D50; 12.3X48 versions prior to 12.3X48-D30; 12.3R versions prior to 12.3R12-S7; 14.1 versions prior to 14.1R8-S4, 14.1R9; 14.1X53 versions prior to 14.1X53-D30, 14.1X53-D34; 14.2 versions prior to 14.2R8; 15.1 versions prior to 15.1F6, 15.1R3; 15.1X49 versions prior to 15.1X49-D40; 15.1X53 versions prior to 15.1X53-D31, 15.1X53-D33, 15.1X53-D60. No other Juniper Networks products or platforms are affected by this issue.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper_networks | junos_os | >= 12.1X46 < 12.1X46-D50 | 12.1X46-D50 |
| juniper_networks | junos_os | >= 12.3R < 12.3R12-S7 | 12.3R12-S7 |
| juniper_networks | junos_os | >= 12.3X48 < 12.3X48-D30 | 12.3X48-D30 |
| juniper_networks | junos_os | >= 14.1 < 14.1R8-S4, 14.1R9 | 14.1R8-S4, 14.1R9 |
| juniper_networks | junos_os | >= 14.1X53 < 14.1X53-D30, 14.1X53-D34 | 14.1X53-D30, 14.1X53-D34 |
| juniper_networks | junos_os | >= 14.2 < 14.2R8 | 14.2R8 |
| juniper_networks | junos_os | >= 15.1 < 15.1F6, 15.1R3 | 15.1F6, 15.1R3 |
| juniper_networks | junos_os | >= 15.1X49 < 15.1X49-D40 | 15.1X49-D40 |
| juniper_networks | junos_os | >= 15.1X53 < 15.1X53-D31, 15.1X53-D33, 15.1X53-D60 | 15.1X53-D31, 15.1X53-D33, 15.1X53-D60 |
| mercurial | mercurial | >= 0 < 4.6.1 | 4.6.1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mercurial: Missing check for fragment start position in mpatch.c:mpatch_apply()
vendor_redhat·2018-06-06·CVSS 7.5
CVE-2018-13346 [HIGH] CWE-20 mercurial: Missing check for fragment start position in mpatch.c:mpatch_apply()
mercurial: Missing check for fragment start position in mpatch.c:mpatch_apply()
The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
Package: mercurial (Red Hat Enterprise Linux 6) - Will not fix
Package: mercurial (Red Hat Enterprise Linux 8) - Not affected
Juniper
CVE-2018-0004: A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS regis
vendor_juniper·2018-01-10·CVSS 6.5
CVE-2018-0004 [MEDIUM] CWE-400 CVE-2018-0004: A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS regis
CVE-2018-0004: A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsystem when a specific command is issued to the device. This affects one or more threads and conversely one or more running processes running on the system. Once this occurs, the high CPU event(s) affects either or both the forwarding and control plane. As a result of this condition the device can become inaccessible in either or both the control and forwarding plane and stops forwarding traffic until the device is rebooted. The issue will reoccur after reboot upon receiving further transit traffic. Score: 5.7 MEDIUM (CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) For network design
GHSA
GHSA-q499-5p9h-r886: A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS regis
ghsa_unreviewed·2022-05-13
CVE-2018-0004 [HIGH] CWE-400 GHSA-q499-5p9h-r886: A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS regis
A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsystem when a specific command is issued to the device. This affects one or more threads and conversely one or more running processes running on the system. Once this occurs, the high CPU event(s) affects either or both the forwarding and control plane. As a result of this condition the device can become inaccessible in either or both the control and forwarding plane and stops forwarding traffic until the device is rebooted. The issue will reoccur after reboot upon receiving further transit traffic. Score: 5.7 MEDIUM (CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) For network designs utilizing lay
GHSA
Mercurial Improper Input Validation vulnerability
ghsa·2022-05-13
CVE-2018-13346 [HIGH] CWE-20 Mercurial Improper Input Validation vulnerability
Mercurial Improper Input Validation vulnerability
The `mpatch_apply` function in `mpatch.c` in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-4204 webkitgtk: memory corruption processing maliciously crafted web content
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4204 [HIGH] CVE-2018-4204 webkitgtk: memory corruption processing maliciously crafted web content
CVE-2018-4204 webkitgtk: memory corruption processing maliciously crafted web content
A flaw was found in WebKitGTK+ before version 2.20.1. A memory corruption issue when processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://webkitgtk.org/security/WSA-2018-0004.html
Discussion:
Created mingw-webkitgtk tracking bugs for this issue:
Affects: fedora-all [bug 1577375]
Created mingw-webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1577380]
Created webkitgtk tracking bugs for this issue:
Affects: epel-all [bug 1577378]
Affects: fedora-all [bug 1577377]
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1577379]
---
Upstream bug report:
https://bugs.chromium.org/p/project-zero/issues/detail?id=
Bugzilla
CVE-2018-4121 webkitgtk: memory corruption processing maliciously crafted web content
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121 webkitgtk: memory corruption processing maliciously crafted web content
CVE-2018-4121 webkitgtk: memory corruption processing maliciously crafted web content
A flaw was found in WebKitGTK+ before version 2.20.0. A memory corruption issue when processing maliciously crafted web content may lead to arbitrary code execution. processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://webkitgtk.org/security/WSA-2018-0004.html
Discussion:
Created mingw-webkitgtk tracking bugs for this issue:
Affects: fedora-all [bug 1577375]
Created mingw-webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1577380]
Created webkitgtk tracking bugs for this issue:
Affects: epel-all [bug 1577378]
Affects: fedora-all [bug 1577377]
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1577379]
Bugzilla
CVE-2018-4200 webkitgtk: memory corruption processing maliciously crafted web content
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4200 [HIGH] CVE-2018-4200 webkitgtk: memory corruption processing maliciously crafted web content
CVE-2018-4200 webkitgtk: memory corruption processing maliciously crafted web content
A flaw was found in WebKitGTK+ before version 2.20.2. A memory corruption issue when processing maliciously crafted web content may lead to arbitrary code execution. processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://webkitgtk.org/security/WSA-2018-0004.html
Discussion:
Created mingw-webkitgtk tracking bugs for this issue:
Affects: fedora-all [bug 1577375]
Created mingw-webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1577380]
Created webkitgtk tracking bugs for this issue:
Affects: epel-all [bug 1577378]
Affects: fedora-all [bug 1577377]
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1577379]
Bugzilla
CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
bugzilla·2018-03-01·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
An incomplete fix for CVE-2018-5748 that affects QEMU monitor leading to a resource exhaustion but now also triggered via QEMU guest agent.
Upstream patch:
https://libvirt.org/git/?p=libvirt.git;a=commit;h=fbf31e1a4cd19d6f6e33e0937a009775cd7d9513
Discussion:
Created mingw-libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1559517]
---
Acknowledgments:
Name: Daniel P. Berrange (Red Hat)
---
External References:
https://security.libvirt.org/2018/0004.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1396 https://access.redhat.com/errata/RHSA-2018:1396
---
This issue has been addressed in the following products:
Red Hat E
Bugzilla
CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
bugzilla·2017-10-09·CVSS 7.0
CVE-2017-12189 [HIGH] CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
It was reported that the jbossas init script performed unsafe file handling, which could result in local privilege escalation.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2018:0003 https://access.redhat.com/errata/RHSA-2018:0003
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
Via RHSA-2018:0002 https://access.redhat.com/errata/RHSA-2018:0002
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
Via RHSA-2018:0004 https://access.
2018-01-10
Published