CVE-2018-3846 is a stack-based buffer overflow vulnerability in NASA CFITSIO versions 3.42 and earlier, affecting products like fedoraproject cfitsio and fedoraproject fedora. This high-severity flaw (CVSS 8.8) allows an unauthenticated attacker to achieve remote code execution by tricking a user into parsing a specially crafted FIT image. While the vulnerability is critical, there is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.42CPE matchmatch criteria | cpe:2.3:a:nasa:cfitsio:3.42:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.