383
VMScore

CVE-2018-10689

Published: 03/05/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

blktrace project blktrace 1.2.0

Vendor Advisories

Synopsis Low: blktrace security update Type/Severity Security Advisory: Low Topic An update for blktrace is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a d ...
Debian Bug report logs - #897695 blktrace: CVE-2018-10689: Buffer overflow in the dev_map_read function Package: src:blktrace; Maintainer for src:blktrace is Bas Zoetekouw <bas@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 4 May 2018 12:24:01 UTC Severity: normal Tags: patch, security ...
blktrace (aka Block IO Tracing) 120, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmapc because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file (CVE-2018-10689) ...
blktrace (aka Block IO Tracing) 120, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmapc because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file(CVE-2018-10689) ...
blktrace (aka Block IO Tracing) 120, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmapc because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file ...