Vulnerability Description
Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Tftp Server Project | Open Tftp Server | <= 1.65 |
Related Weaknesses (CWE)
References
- https://sourceforge.net/p/tftp-server/discussion/550564/thread/a586ce62/PatchThird Party Advisory
- https://sourceforge.net/p/tftp-server/discussion/550564/thread/a586ce62/PatchThird Party Advisory
FAQ
What is CVE-2018-10389?
CVE-2018-10389 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a...
How severe is CVE-2018-10389?
CVE-2018-10389 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-10389?
Check the references section above for vendor advisories and patch information. Affected products include: Open Tftp Server Project Open Tftp Server.