CVE-2018-10237

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
googleguava
11.0 ≤
𝑥
< 24.1.1
redhatopenshift_container_platform
3.11
redhatsatellite
6.4
redhatsatellite_capsule
6.4
redhatvirtualization
4.2
redhatvirtualization_host
4.0
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.4.0
redhatjboss_enterprise_application_platform
7.1.0
redhatopenshift_container_platform
4.1
redhatvirtualization
4.0
redhatvirtualization_host
4.0
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.4.0
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.4.0
redhatjboss_enterprise_application_platform
7.1.0
oraclebanking_payments
14.1.0 ≤
𝑥
≤ 14.4.0
oraclecommunications_ip_service_activator
7.3.0
oraclecommunications_ip_service_activator
7.4.0
oraclecustomer_management_and_segmentation_foundation
18.0
oracledatabase_server
12.2.0.1
oracleflexcube_investor_servicing
12.1.0
oracleflexcube_investor_servicing
12.3.0
oracleflexcube_investor_servicing
12.4.0
oracleflexcube_investor_servicing
14.0.0
oracleflexcube_investor_servicing
14.1.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oracleretail_integration_bus
15.0
oracleretail_integration_bus
16.0
oracleretail_xstore_point_of_service
7.1
oracleretail_xstore_point_of_service
15.0
oracleretail_xstore_point_of_service
16.0
oracleretail_xstore_point_of_service
17.0
oracleweblogic_server
12.2.1.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
guava-libraries
bullseye
29.0-6
fixed
buster
postponed
bookworm
31.1-1
fixed
sid
32.0.1-1
fixed
trixie
32.0.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
guava-libraries
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage
References