CVE-2018-10360: Medium severity IBM Data Risk Manager vulnerability
File is vulnerable to a denial of service, caused by an out-of-bounds read in the docorenote function in readelf.c in libmagic.a. By persuading a victim to open a specially crafted ELF file, a remote attacker could exploit this vulnerability to cause a denial of service.
Other sources
The docorenote function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-10360.
What is the severity of CVE-2018-10360?
The severity of CVE-2018-10360 is medium with a CVSS score of 6.5.
How does CVE-2018-10360 affect the affected software?
CVE-2018-10360 can cause a denial of service in the affected software.
Which version of the affected software is vulnerable to CVE-2018-10360?
The version 1:5.33-3 of the affected software is vulnerable to CVE-2018-10360.
How can I fix CVE-2018-10360?
To fix CVE-2018-10360, update the affected software to version 1:5.33-3 or later.