CVE-2018-15688
published 2018-10-26CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases…
high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | network-manager | < network-manager 1.14.4-2 (bookworm) | network-manager 1.14.4-2 (bookworm) |
| debian | systemd | < network-manager 1.14.4-2 (bookworm) | network-manager 1.14.4-2 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-31_on_cbl_mariner_1.0 | — | — |
| network-manager_project | network-manager | >= 0 < 1.14.4-2 | 1.14.4-2 |
| network-manager_project | network-manager | >= 0 < 1.14.4-2 | 1.14.4-2 |
| network-manager_project | network-manager | >= 0 < 1.14.4-2 | 1.14.4-2 |
| network-manager_project | network-manager | >= 0 < 1.14.4-2 | 1.14.4-2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| systemd | systemd | unspecified – 239 | — |
| systemd_project | systemd | <= 239 | — |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH