CVE-2018-10237
26.04.2018, 21:29
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.Enginsight
Vendor | Product | Version |
---|---|---|
guava | 11.0 ≤ 𝑥 < 24.1.1 | |
redhat | openshift_container_platform | 3.11 |
redhat | satellite | 6.4 |
redhat | satellite_capsule | 6.4 |
redhat | virtualization | 4.2 |
redhat | virtualization_host | 4.0 |
redhat | jboss_enterprise_application_platform | 6.0.0 |
redhat | jboss_enterprise_application_platform | 6.4.0 |
redhat | jboss_enterprise_application_platform | 7.1.0 |
redhat | openshift_container_platform | 4.1 |
redhat | virtualization | 4.0 |
redhat | virtualization_host | 4.0 |
redhat | jboss_enterprise_application_platform | 6.0.0 |
redhat | jboss_enterprise_application_platform | 6.4.0 |
redhat | jboss_enterprise_application_platform | 6.0.0 |
redhat | jboss_enterprise_application_platform | 6.4.0 |
redhat | jboss_enterprise_application_platform | 7.1.0 |
oracle | banking_payments | 14.1.0 ≤ 𝑥 ≤ 14.4.0 |
oracle | communications_ip_service_activator | 7.3.0 |
oracle | communications_ip_service_activator | 7.4.0 |
oracle | customer_management_and_segmentation_foundation | 18.0 |
oracle | database_server | 12.2.0.1 |
oracle | flexcube_investor_servicing | 12.1.0 |
oracle | flexcube_investor_servicing | 12.3.0 |
oracle | flexcube_investor_servicing | 12.4.0 |
oracle | flexcube_investor_servicing | 14.0.0 |
oracle | flexcube_investor_servicing | 14.1.0 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | retail_integration_bus | 15.0 |
oracle | retail_integration_bus | 16.0 |
oracle | retail_xstore_point_of_service | 7.1 |
oracle | retail_xstore_point_of_service | 15.0 |
oracle | retail_xstore_point_of_service | 16.0 |
oracle | retail_xstore_point_of_service | 17.0 |
oracle | weblogic_server | 12.2.1.3.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References