CVE-2018-18409 describes a stack-based buffer over-read vulnerability in the setbit() function within iptree.h of TCPFLOW version 1.5.0. This flaw, caused by incorrect value processing, can lead to a denial of service during address_histogram or get_histogram calls, affecting various Canonical, DigitalCorpora, and FedoraProject distributions of TCPFLOW. Rated with a CVSS score of 5.5 (Medium), this vulnerability requires local access and user interaction (UI:R) to trigger, resulting in high availability impact (A:H) but no confidentiality or integrity compromise. There is no evidence of active exploitation, and no public exploit code exists in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0CPE matchmatch criteria | cpe:2.3:a:digitalcorpora:tcpflow:1.5.0:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.