Vulnerability Name:

CVE-2018-9306 (CCN-141367)

Assigned:2018-04-04
Published:2018-04-04
Updated:2018-04-20
Summary:** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.
ConsultIDs: CVE-2017-17724.
Reason: This candidate is a reservation duplicate of CVE-2017-17724.
Notes: All CVE users should reference CVE-2017-17724 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVSS v3 Severity:4.4 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:
Vulnerability Type:CWE-125
References:Source: MITRE
Type: CNA
CVE-2018-9306

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.redhat.rhsa:def:20201577
    P
    RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
    2020-04-28
    oval:com.ubuntu.artful:def:20189306000
    V
    CVE-2018-9306 on Ubuntu 17.10 (artful) - medium.
    2018-04-04
    oval:com.ubuntu.trusty:def:20189306000
    V
    CVE-2018-9306 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-04-04
    oval:com.ubuntu.xenial:def:20189306000
    V
    CVE-2018-9306 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-04-04
    BACK