Vulnerability Database
Blog
FAQ
Docs
CVE-2018-14447
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2018-14447
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14447.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-14447
Related
DLA-1470-1
UBUNTU-CVE-2018-14447
openSUSE-SU-2024:10930-1
Published
2018-07-20T13:29:00Z
Modified
2024-12-05T15:23:55.597220Z
Severity
8.8 (High)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
References
https://github.com/martinh/libconfuse/issues/109
http://hac425.unaux.com/index.php/archives/64/
https://lists.debian.org/debian-lts-announce/2018/08/msg00017.html
https://security.alpinelinux.org/vuln/CVE-2018-14447
Affected packages
Alpine:v3.10
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.11
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.12
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.13
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.14
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.15
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.16
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.17
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.18
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.19
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.20
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.21
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Alpine:v3.9
/
confuse
Package
Name
confuse
Purl
pkg:apk/alpine/confuse?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.2.2-r0
Affected versions
2.*
2.6-r0
2.6-r1
2.7-r0
2.7-r1
2.7-r2
2.7-r3
2.8-r0
3.*
3.0-r0
3.2-r0
3.2.1-r0
Git
/
github.com/martinh/libconfuse
Affected ranges
Type
GIT
Repo
https://github.com/martinh/libconfuse
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
64f27906ce53e503ed2daa96080156f06529c790
Affected versions
Other
V2_6
V2_7
version-2_0
version-2_1
version-2_2
version-2_3
version-2_4
version-2_5
v2.*
v2.0
v2.1
v2.2
v2.3
v2.4
v2.5
v2.6
v2.7
v2.8
v3.*
v3.0
v3.1
v3.2
v3.2.1
CVE-2018-14447 - OSV