VYPR
Medium severity5.5OSV Advisory· Published Oct 17, 2018· Updated Jun 17, 2026

CVE-2018-18409

CVE-2018-18409

Description

A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Simsong/TcpflowOSV2 versions
    push, tcpflow-1.2.5, tcpflow-1.2.7, …+ 1 more
    • (no CPE)range: push, tcpflow-1.2.5, tcpflow-1.2.7, …
    • (no CPE)range: =1.5.0
  • cpe:2.3:a:digitalcorpora:tcpflow:1.5.0:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.