Vulnerability Name:

CVE-2018-1084 (CCN-141586)

Assigned:2017-12-04
Published:2018-04-12
Updated:2023-01-31
Summary:corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-1084

Source: CCN
Type: oss-sec Mailing List, Thu, 12 Apr 2018 14:16:48 +0200
CVE-2018-1084 corosync: Integer overflow in exec/totemcrypto.c:authenticate_nss_2_3() function

Source: CCN
Type: IBM Security Bulletin 878985 (PowerKVM)
A vulnerability in Corosync affects PowerKVM

Source: CCN
Type: BID-103758
Corosync 'exec/totemcrypto.c' Integer Overflow Vulnerability

Source: secalert@redhat.com
Type: Third Party Advisory, VDB Entry
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Third Party Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
corosync-cve20181084-dos(141586)

Source: CCN
Type: corosync GIT Repository
totemcrypto: Check length of the packet

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: IBM Security Bulletin 879045 (MQ)
IBM MQ RDQM and IBM MQ Appliance are vulnerable to a denial of service attack (CVE-2018-1084)

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20181084
    V
    CVE-2018-1084
    2022-09-02
    oval:org.opensuse.security:def:6342
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:15
    P
    bash-4.4-17.83 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:2
    P
    amavisd-new-2.11.1-6.3.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:6331
    P
    Security update for the Linux Kernel (Important)
    2022-05-16
    oval:org.opensuse.security:def:112103
    P
    corosync-2.4.5+git70.64010f57-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:6301
    P
    Security update for openexr (Important)
    2022-01-12
    oval:org.opensuse.security:def:6312
    P
    Security update for gegl (Important)
    2021-12-28
    oval:org.opensuse.security:def:10431
    P
    Security update for xorg-x11-server (Important)
    2021-12-21
    oval:org.opensuse.security:def:10384
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:7293
    P
    Security update for the Linux Kernel (Live Patch 4 for SLE 15 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:6309
    P
    Security update for the Linux Kernel (Important)
    2021-12-02
    oval:org.opensuse.security:def:7282
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:6458
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:10164
    P
    Security update for strongswan (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:7271
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP3) (Important)
    2021-10-12
    oval:org.opensuse.security:def:105640
    P
    corosync-2.4.5+git70.64010f57-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:10338
    P
    Security update for java-11-openjdk (Important)
    2021-09-03
    oval:org.opensuse.security:def:10145
    P
    Security update for dovecot23 (Moderate)
    2021-08-31
    oval:org.opensuse.security:def:10328
    P
    Security update for aws-cli, python-boto3, python-botocore, python-service_identity, python-trustme, python-urllib3 (Moderate)
    2021-08-23
    oval:org.opensuse.security:def:10316
    P
    Security update for webkit2gtk3 (Important)
    2021-08-17
    oval:org.opensuse.security:def:10315
    P
    Security update for c-ares (Important)
    2021-08-17
    oval:org.opensuse.security:def:10130
    P
    Security update for webkit2gtk3 (Important)
    2021-08-17
    oval:org.opensuse.security:def:7260
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP3) (Important)
    2021-08-17
    oval:org.opensuse.security:def:13896
    P
    libevent-2_0-5-2.0.21-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13964
    P
    libtasn1-3.7-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13942
    P
    libpng16-16-1.6.8-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13918
    P
    libjpeg-turbo-1.3.1-30.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:10308
    P
    Security update for linuxptp (Important)
    2021-07-27
    oval:org.opensuse.security:def:10306
    P
    Security update for curl (Moderate)
    2021-07-21
    oval:org.opensuse.security:def:6450
    P
    Security update for the Linux Kernel (Important)
    2021-07-14
    oval:org.opensuse.security:def:67538
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:6469
    P
    Security update for postgresql10 (Moderate)
    2021-06-14
    oval:org.opensuse.security:def:13304
    P
    gdm-3.10.0.1-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:123985
    P
    corosync-2.3.6-9.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13291
    P
    elfutils-0.158-3.200 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12790
    P
    corosync-2.3.6-9.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13282
    P
    cvs-1.12.12-181.54 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:124507
    P
    libcorosync-devel-2.3.6-9.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70891
    P
    dhcp-4.3.5-4.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11289
    P
    dracut-037-34.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16501
    P
    libcorosync-devel-2.3.6-9.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11267
    P
    bash-4.2-75.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13258
    P
    apache-commons-daemon-1.0.15-4.181 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:10264
    P
    Security update for nginx (Important)
    2021-06-02
    oval:org.opensuse.security:def:10083
    P
    Security update for nginx (Important)
    2021-05-27
    oval:org.opensuse.security:def:13239
    P
    libopenssl0_9_8-0.9.8j-59.11 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:70778
    P
    Security update for the Linux Kernel (Important)
    2021-04-16
    oval:org.opensuse.security:def:10239
    P
    Security update for xorg-x11-server (Important)
    2021-04-14
    oval:org.opensuse.security:def:6320
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:10037
    P
    Security update for flac (Moderate)
    2020-12-24
    oval:org.opensuse.security:def:12937
    P
    libFLAC++6-1.3.0-11.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89535
    P
    corosync-2.4.4-7.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12982
    P
    libexempi3-2.2.1-5.7.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13194
    P
    tboot-20190704_1.9.10-1.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13169
    P
    rsync-3.1.3-1.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13094
    P
    libvpx1-1.3.0-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12801
    P
    corosync-2.3.6-9.13.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13075
    P
    libssh4-0.8.7-1.31 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13060
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13013
    P
    libksba8-1.3.0-23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12967
    P
    libapr1-1.5.1-4.5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:96500
    P
    corosync-2.4.4-7.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12945
    P
    libX11-6-1.6.2-12.5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13214
    P
    xen-4.12.1_06-1.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13139
    P
    perl-DBD-mysql-4.021-12.5.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13120
    P
    ntp-4.2.8p13-85.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13105
    P
    libykcs11-1-1.5.0-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13058
    P
    libqt4-32bit-4.8.7-8.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13012
    P
    libkpathsea6-6.2.0dev-22.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:3967
    P
    libcorosync-devel-2.3.6-9.13.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12990
    P
    libgme0-0.6.0-5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13245
    P
    apache2-mod_php7-7.0.7-15.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103190
    P
    corosync-2.4.4-7.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13236
    P
    libslurm29-16.05.8.1-5.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16803
    P
    libcorosync-devel-2.3.6-9.13.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:6439
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-02
    oval:org.opensuse.security:def:10015
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17798
    P
    Security update for ocaml (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6620
    P
    gpg2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17767
    P
    Security update for ldb, samba, talloc, tdb, tevent (Important)
    2020-12-01
    oval:org.opensuse.security:def:6611
    P
    ghostscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17710
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:10565
    P
    libxml2-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17625
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10540
    P
    libserf-1-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17591
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:10465
    P
    libX11-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10446
    P
    gnome-online-accounts-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6591
    P
    ecryptfs-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67438
    P
    Security update for python-pip (Important)
    2020-12-01
    oval:org.opensuse.security:def:6558
    P
    autofs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6533
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10988
    P
    libcorosync-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6424
    P
    libpython3_4m1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6377
    P
    libgc1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18067
    P
    Security update for libgme (Important)
    2020-12-01
    oval:org.opensuse.security:def:18045
    P
    Recommended update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:18033
    P
    Security update for sudo (Important)
    2020-12-01
    oval:org.opensuse.security:def:18731
    P
    Security update for corosync (Important)
    2020-12-01
    oval:org.opensuse.security:def:10007
    P
    unzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6602
    P
    fontconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6569
    P
    coolkey on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10966
    P
    libXrandr-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6544
    P
    yast2-users on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10629
    P
    augeas-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10616
    P
    FastCGI on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17583
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10607
    P
    wireshark-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6435
    P
    libspice-client-glib-2_0-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18705
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:6388
    P
    libjasper1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6622
    P
    groff on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6609
    P
    gdm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64191
    P
    corosync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6600
    P
    file on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17976
    P
    Security update for php5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:64104
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17944
    P
    Security update for poppler (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17834
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6633
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20181169
    P
    RHSA-2018:1169: corosync security update (Important)
    2018-04-17
    oval:com.ubuntu.trusty:def:20181084000
    V
    CVE-2018-1084 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-04-13
    oval:com.ubuntu.artful:def:20181084000
    V
    CVE-2018-1084 on Ubuntu 17.10 (artful) - medium.
    2018-04-13
    oval:com.ubuntu.xenial:def:20181084000
    V
    CVE-2018-1084 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-04-13
    oval:com.ubuntu.cosmic:def:201810840000000
    V
    CVE-2018-1084 on Ubuntu 18.10 (cosmic) - medium.
    2018-04-12
    oval:com.ubuntu.bionic:def:201810840000000
    V
    CVE-2018-1084 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-04-12
    oval:com.ubuntu.xenial:def:201810840000000
    V
    CVE-2018-1084 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-04-12
    oval:com.ubuntu.bionic:def:20181084000
    V
    CVE-2018-1084 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-04-12
    oval:com.ubuntu.cosmic:def:20181084000
    V
    CVE-2018-1084 on Ubuntu 18.10 (cosmic) - medium.
    2018-04-12
    BACK