CVE-2018-21028: High severity boa boa vulnerability
Published Oct 11, 2019
·Updated
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
Affected Software
1 affected component
Boa Boa<=0.94.14.21
Remediation
Event History
Oct 11, 2019
CVE Published
via MITRE·07:29 PM
Data Sourced
via MITRE·07:29 PM
Description
Frequently Asked Questions
1
What is CVE-2018-21028?
CVE-2018-21028 is a vulnerability in Boa 0.94.14rc21 that allows remote attackers to trigger a memory leak due to missing calls to the free function.
2
How does Boa 0.94.14rc21 allow remote attackers to trigger a memory leak?
Boa 0.94.14rc21 allows remote attackers to trigger a memory leak by not making the necessary calls to the free function.
3
What is the severity of CVE-2018-21028?
CVE-2018-21028 has a severity level of high, with a CVSS score of 7.5.
4
What software versions are affected by CVE-2018-21028?
CVE-2018-21028 affects Boa versions up to and including 0.94.14rc21.
5
How can I fix CVE-2018-21028?
To fix CVE-2018-21028, update Boa to a version that includes the fix.