CVE-2018-2918

CWE-1846 documents5 sources
Severity
7.5HIGH
EPSS
3.7%
top 12.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 13

Description

Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks). The supported version that is affected is Prior to 8.7.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Sun ZFS Storage Appliance Kit (AK). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeove

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hmvp-993j-38fx: Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks)2022-05-13
CVEList
CVE-2018-2918: Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: API frameworks)2018-07-18

📋Vendor Advisories

1
Red Hat
ghostscript: incomplete fix for CVE-2018-165092018-12-03

💬Community

2
Bugzilla
CVE-2018-16863 ghostscript: incomplete fix for CVE-2018-165092018-11-23
Bugzilla
CVE-2018-16542 ghostscript: .definemodifiedfont memory corruption if /typecheck is handled (699668)2018-08-23