CVE-2018-2918
published 2018-07-18CVE-2018-2918: Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks). The supported version…
PriorityP342high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EPSS
2.39%
82.1th percentile
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks). The supported version that is affected is Prior to 8.7.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Sun ZFS Storage Appliance Kit (AK). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | sun_zfs_storage_appliance_kit | < 8.7.18 | 8.7.18 |
| oracle_corporation | sun_zfs_storage_appliance_kit_software | >= unspecified < 8.7.18 | 8.7.18 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hmvp-993j-38fx: Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks)
ghsa_unreviewed·2022-05-13
CVE-2018-2918 [HIGH] GHSA-hmvp-993j-38fx: Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks)
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks). The supported version that is affected is Prior to 8.7.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Sun ZFS Storage Appliance Kit (AK). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Red Hat
ghostscript: incomplete fix for CVE-2018-16509
vendor_redhat·2018-12-03·CVSS 7.8
CVE-2018-16863 [HIGH] CWE-184 ghostscript: incomplete fix for CVE-2018-16509
ghostscript: incomplete fix for CVE-2018-16509
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document.
Statement: This vulnerability affects only Red Hat Enterprise Linux version 7. Red Hat Enterprise Linux version 6 is not affected by this vulnerability b
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16863 ghostscript: incomplete fix for CVE-2018-16509
bugzilla·2018-11-23·CVSS 7.8
CVE-2018-16863 [HIGH] CVE-2018-16863 ghostscript: incomplete fix for CVE-2018-16509
CVE-2018-16863 ghostscript: incomplete fix for CVE-2018-16509
It was found that the fix for CVE-2018-16509 provided in Red Hat Enterprise Linux 7 was not sufficient.
Discussion:
The full fix for CVE-2018-16509 (bug 1619748) consists of the following 4 upstream patches:
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=5516c614dc33
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=78911a01b67d
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=79cccf641486
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=520bb0ea7519
The RHSA-2018:2918 erratum for Red Hat Enterprise Linux 7 only included the first 2 fixes, and hence failed to fix CVE-2018-16509 completely.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3761 http
Bugzilla
CVE-2018-16542 ghostscript: .definemodifiedfont memory corruption if /typecheck is handled (699668)
bugzilla·2018-08-23·CVSS 7.8
CVE-2018-16542 [HIGH] CVE-2018-16542 ghostscript: .definemodifiedfont memory corruption if /typecheck is handled (699668)
CVE-2018-16542 ghostscript: .definemodifiedfont memory corruption if /typecheck is handled (699668)
It was discovered that ghostscript did not properly handle certain stack overflow error conditions. A specially crafted PostScript document could exploit this to crash ghostscript or, possibly, execute arbitrary code in the context of the ghostscript process.
Patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=b575e1ec42
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1625827]
---
Acknowledgments:
Name: Tavis Ormandy (Google Project Zero)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:2918 https://access.redhat.com/errata/RHSA-2018:2918
---
Statement:
This issue affects t
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104783http://www.securitytracker.com/id/1041303http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104783http://www.securitytracker.com/id/1041303
2018-07-18
Published