CVE-2018-14634
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
Affected (97)
Products: Paloaltonetworks: Pan Os · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Iq Centralized Management, Big Iq Cloud And Orchestration, Enterprise Manager, Iworkflow, Traffix Signaling Delivery Controller · Linux: Linux Kernel · +3 more
Show all products
Paloaltonetworks: Pan Os · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Iq Centralized Management, Big Iq Cloud And Orchestration, Enterprise Manager, Iworkflow, Traffix Signaling Delivery Controller · Linux: Linux Kernel · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation · Canonical: Ubuntu Linux · Netapp: Snapprotect
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.1.0 to 7.1.23 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 | |
| From 11.2.1 to 11.6.4 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.0.0 to 5.4.0 | |
| Version 1.0.0 | |
| Version 3.1.1 | |
| From 2.2.0 to 2.3.0 | |
| From 5.0.0 to 5.1.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.6.0 to 2.6.39.4 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.0 | |
| Version 6.5 | |
| Version 6.7 | |
| Version 6.6 | |
| Version 6.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.04 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (45)
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB EntryBroken Link
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB EntryBroken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.