CVE-2018-18439

DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
denxu-boot
𝑥
< 2018.09
denxu-boot
2018.09:rc1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
u-boot
bookworm
unimportant
bullseye
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
u-boot
bionic
not-affected
cosmic
ignored
disco
ignored
eoan
ignored
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
u-boot-rpiarm64
suse enterprise desktop 15 SP2
2020.01-8.3
fixed
suse enterprise desktop 15 SP3
2021.01-5.1
fixed
suse enterprise desktop 15 SP4
2021.10-150400.2.6
fixed
suse enterprise desktop 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise desktop 15 SP6
2021.10-150600.9.2
fixed
suse enterprise desktop 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise sap 15 SP2
2020.01-8.3
fixed
suse enterprise sap 15 SP3
2021.01-5.1
fixed
suse enterprise sap 15 SP4
2021.10-150400.2.6
fixed
suse enterprise sap 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise sap 15 SP6
2021.10-150600.9.2
fixed
suse enterprise sap 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise server 15 SP2
2020.01-8.3
fixed
suse enterprise server 15 SP3
2021.01-5.1
fixed
suse enterprise server 15 SP4
2021.10-150400.2.6
fixed
suse enterprise server 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise server 15 SP6
2021.10-150600.9.2
fixed
suse enterprise server 15 SP7
2021.10-150600.11.3.1
fixed
u-boot-rpiarm64-doc
suse enterprise desktop 15 SP2
2020.01-8.3
fixed
suse enterprise desktop 15 SP3
2021.01-5.1
fixed
suse enterprise desktop 15 SP4
2021.10-150400.2.6
fixed
suse enterprise desktop 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise desktop 15 SP6
2021.10-150600.9.2
fixed
suse enterprise desktop 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise sap 15 SP2
2020.01-8.3
fixed
suse enterprise sap 15 SP3
2021.01-5.1
fixed
suse enterprise sap 15 SP4
2021.10-150400.2.6
fixed
suse enterprise sap 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise sap 15 SP6
2021.10-150600.9.2
fixed
suse enterprise sap 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise server 15 SP2
2020.01-8.3
fixed
suse enterprise server 15 SP3
2021.01-5.1
fixed
suse enterprise server 15 SP4
2021.10-150400.2.6
fixed
suse enterprise server 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise server 15 SP6
2021.10-150600.9.2
fixed
suse enterprise server 15 SP7
2021.10-150600.11.3.1
fixed
u-boot-tools
suse enterprise desktop 15 SP2
2020.01-8.3
fixed
suse enterprise desktop 15 SP3
2021.01-5.1
fixed
suse enterprise desktop 15 SP4
2021.10-150400.2.7
fixed
suse enterprise desktop 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise desktop 15 SP6
2021.10-150600.9.3
fixed
suse enterprise desktop 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise sap 15 SP2
2020.01-8.3
fixed
suse enterprise sap 15 SP3
2021.01-5.1
fixed
suse enterprise sap 15 SP4
2021.10-150400.2.7
fixed
suse enterprise sap 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise sap 15 SP6
2021.10-150600.9.3
fixed
suse enterprise sap 15 SP7
2021.10-150600.11.3.1
fixed
suse enterprise server 15 SP2
2020.01-8.3
fixed
suse enterprise server 15 SP3
2021.01-5.1
fixed
suse enterprise server 15 SP4
2021.10-150400.2.7
fixed
suse enterprise server 15 SP5
2021.10-150400.4.11.1
fixed
suse enterprise server 15 SP6
2021.10-150600.9.3
fixed
suse enterprise server 15 SP7
2021.10-150600.11.3.1
fixed