Home
Packages
Vulnerabilities
Vendors
Report
Policy
Login
Signup
« List of all CVEs
CVE-2018-1084
Published:
4/12/2018
Last updated:
8/5/2024
Reserved:
12/4/2017
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
CNA assigner:
redhat (53f830b8-0a3f-465b-8143-3b8a9948e749)
Requested by:
n/a
Metrics
Version
Score
Severity
Vector String
3.0
7.5
High
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Opam packages affected (1)
conf-libcorosync
Products affected (1)
Product
Vendor
Version
corosync
unspecified
SA8650P
References (12)
http://www.securityfocus.com/bid/103758
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1084
https://www.debian.org/security/2018/dsa-4174
https://access.redhat.com/errata/RHSA-2018:1169
https://usn.ubuntu.com/4000-1/
https://security.gentoo.org/glsa/202107-01
http://www.securityfocus.com/bid/103758
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1084
https://www.debian.org/security/2018/dsa-4174
https://access.redhat.com/errata/RHSA-2018:1169
https://usn.ubuntu.com/4000-1/
https://security.gentoo.org/glsa/202107-01