Vulnerability Description
tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial of Service (system crash) due to incorrect I/O port access control on the i386 architecture.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openbsd | 6.2 |
Related Weaknesses (CWE)
References
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/sys/arch/i386/i386/gdt.cIssue TrackingPatchVendor Advisory
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/sys/arch/i386/i386/gdt.c.diff?r1=1.PatchVendor Advisory
- http://www.securitytracker.com/id/1041550Third Party AdvisoryVDB Entry
- https://ftp.openbsd.org/pub/OpenBSD/patches/6.2/common/020_ioport.patch.sigPatchVendor Advisory
- https://ftp.openbsd.org/pub/OpenBSD/patches/6.3/common/015_ioport.patch.sigPatchVendor Advisory
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/sys/arch/i386/i386/gdt.cIssue TrackingPatchVendor Advisory
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/sys/arch/i386/i386/gdt.c.diff?r1=1.PatchVendor Advisory
- http://www.securitytracker.com/id/1041550Third Party AdvisoryVDB Entry
- https://ftp.openbsd.org/pub/OpenBSD/patches/6.2/common/020_ioport.patch.sigPatchVendor Advisory
- https://ftp.openbsd.org/pub/OpenBSD/patches/6.3/common/015_ioport.patch.sigPatchVendor Advisory
FAQ
What is CVE-2018-14775?
CVE-2018-14775 is a vulnerability with a CVSS score of 5.5 (MEDIUM). tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial of Service (system crash) due to incorrect I/O port access control on the i386 architecture.
How severe is CVE-2018-14775?
CVE-2018-14775 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14775?
Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openbsd.