7.8

CVE-2018-10878

Exploit
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version18.04 SwEditionlts
LinuxLinux Kernel Version < 3.16.58
LinuxLinux Kernel Version >= 3.17 < 3.18.124
LinuxLinux Kernel Version >= 3.19 < 4.4.140
LinuxLinux Kernel Version >= 4.5 < 4.9.112
LinuxLinux Kernel Version >= 4.10 < 4.14.55
LinuxLinux Kernel Version >= 4.15 < 4.17.6
DebianDebian Linux Version8.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.168
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.1 3.9 8.5
AV:L/AC:L/Au:N/C:P/I:P/A:C
secalert@redhat.com 4.8 0.5 4.2
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.