CVE-2018-6918
published 2018-04-04CVE-2018-6918: In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.38%
90.2th percentile
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote attacker who is able to send an arbitrary packet to cause the machine to crash.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | airport_base_station_firmware_update | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | >= 10.0 < 10.4 | 10.4 |
| freebsd | freebsd | >= 11.0 < 11.1 | 11.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-6918: AirPort Base Station Firmware Update 7.8.1
vendor_apple·2019-06-20·CVSS 7.5
CVE-2018-6918 [HIGH] CVE-2018-6918: AirPort Base Station Firmware Update 7.8.1
Apple Security Update: About the security content of AirPort Base Station Firmware Update 7.8.1
Product: AirPort Base Station Firmware Update
Version: 7.8.1
CVE: CVE-2018-6918
Component: AirPort Base Station Firmware
Impact: A remote attacker may be able to cause a system denial of service
Description: A denial of service issue was addressed with improved validation.
BSD
FreeBSD-SA-18:05.ipsec: ipsec crash or denial of service
bsd_advisories·2018-04-04·CVSS 7.5
CVE-2018-6918 [HIGH] FreeBSD-SA-18:05.ipsec: ipsec crash or denial of service
FreeBSD-SA-18:05.ipsec Security Advisory
The FreeBSD Project
Topic: ipsec crash or denial of service
Category: core
Module: ipsec
Announced: 2018-04-04
Credits: Maxime Villard
Affects: All supported versions of FreeBSD.
Corrected: 2018-01-31 09:24:48 UTC (stable/11, 11.1-STABLE)
2018-04-04 05:37:52 UTC (releng/11.1, 11.1-RELEASE-p9)
2018-01-31 09:26:28 UTC (stable/10, 10.4-STABLE)
2018-04-04 05:37:52 UTC (releng/10.4, 10.4-RELEASE-p8)
2018-04-04 05:37:52 UTC (releng/10.3, 10.3-RELEASE-p29)
CVE Name: CVE-2018-6918
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The IPsec suite of protocols provide network level security for IPv4 and IPv6
packets. FreeBS
GHSA
GHSA-v4xf-p7r4-pfpq: In FreeBSD before 11
ghsa_unreviewed·2022-05-13
CVE-2018-6918 [HIGH] CWE-835 GHSA-v4xf-p7r4-pfpq: In FreeBSD before 11
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote attacker who is able to send an arbitrary packet to cause the machine to crash.
No detection rules found.
No public exploits indexed.
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
# Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative
2022/07/27
Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service, VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c. In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP s
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative 2022/07/27 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative Jul 27, 2022 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/
http://seclists.org/fulldisclosure/2019/Jun/6http://www.securityfocus.com/bid/103666http://www.securitytracker.com/id/1040628https://seclists.org/bugtraq/2019/May/77https://security.FreeBSD.org/advisories/FreeBSD-SA-18:05.ipsec.aschttps://support.apple.com/kb/HT210090https://support.apple.com/kb/HT210091http://seclists.org/fulldisclosure/2019/Jun/6http://www.securityfocus.com/bid/103666http://www.securitytracker.com/id/1040628https://seclists.org/bugtraq/2019/May/77https://security.FreeBSD.org/advisories/FreeBSD-SA-18:05.ipsec.aschttps://support.apple.com/kb/HT210090https://support.apple.com/kb/HT210091
2018-04-04
Published