Executive Summary

Informations
NameCVE-2018-1330First vendor Publication2018-09-13
VendorCveLast vendor Modification2019-01-29

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score5Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityLow
Cvss Expoit Score10AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1330

CWE : Common Weakness Enumeration

%idName
100 %CWE-20Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application9

Sources (Detail)

SourceUrl
MLIST https://lists.apache.org/thread.html/395cb6bcf367702acd1e580a1f39b56cdd7a5953...

Alert History

If you want to see full details history, please login or register.
0
1
DateInformations
2019-01-29 17:19:10
  • Multiple Updates
2018-09-14 13:20:37
  • First insertion