Vulnerability Description
A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is present in the parsing of a network packet without proper validation of the packet. The data read by the application is not validated, and its use can lead to a null pointer dereference. The IT application is opened by a user and then listens for a connection on port 4001. An attacker can deliver an attack once the application has been opened.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pixar | Renderman | 21.6 |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0523ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0523ExploitThird Party Advisory
FAQ
What is CVE-2018-3840?
CVE-2018-3840 is a vulnerability with a CVSS score of 7.5 (HIGH). A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is present in the parsing of a network packet without proper validation of the packet....
How severe is CVE-2018-3840?
CVE-2018-3840 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-3840?
Check the references section above for vendor advisories and patch information. Affected products include: Pixar Renderman.