Wind River Support Network

HomeDefectsLIN1018-5152
Fixed

LIN1018-5152 : Security Advisory - file - CVE-2019-18218

Created: Oct 22, 2019    Updated: Apr 21, 2022
Resolved Date: Nov 3, 2019
Found In Version: 10.18.44.1
Fix Version: 10.18.44.12
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

CREATE(Triage):(User=admin) CVE-2019-18218 (https://nvd.nist.gov/vuln/detail/CVE-2019-18218)

CVEs


Live chat
Online