VulnerabilityModified
CVE-2018-17158
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request.
HIGH 7.5EPSS 4.41%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request. Unprivileged remote users with access to the NFS server can crash the system by sending a specially crafted NFSv4 request.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 4.41% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- freebsd/freebsd
- Source
- secteam@freebsd.org
References
- http://www.securityfocus.com/bid/106192Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042164Third Party Advisory, VDB Entry
- https://secuniaresearch.flexerasoftware.com/secunia_research/2018-24/Third Party Advisory
- https://security.freebsd.org/advisories/FreeBSD-SA-18:13.nfs.ascThird Party Advisory
- http://www.securityfocus.com/bid/106192Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042164Third Party Advisory, VDB Entry
- https://secuniaresearch.flexerasoftware.com/secunia_research/2018-24/Third Party Advisory
- https://security.freebsd.org/advisories/FreeBSD-SA-18:13.nfs.ascThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.