cbcvebase.
CVE-2018-6918
published 2018-04-04

CVE-2018-6918: In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count…

PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.38%
90.2th percentile
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote attacker who is able to send an arbitrary packet to cause the machine to crash.

Affected

4 ranges
VendorProductVersion rangeFixed in
appleairport_base_station_firmware_update
freebsdfreebsd
freebsdfreebsd>= 10.0 < 10.410.4
freebsdfreebsd>= 11.0 < 11.111.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.