UBUNTU-CVE-2018-1000875

Source
https://ubuntu.com/security/CVE-2018-1000875
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000875.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-1000875
Upstream
  • CVE-2018-1000875
Withdrawn
2025-08-01T19:36:15Z
Published
2018-12-20T17:29:00Z
Modified
2025-08-01T04:51:23Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account. This attack appear to be exploitable via Specially crafted URL. This vulnerability appears to have been fixed in 1.0.3.

References

Affected packages

Ubuntu:Pro:16.04:LTS / boinc

Package

Name
boinc
Purl
pkg:deb/ubuntu/boinc@7.6.31+dfsg-6ubuntu1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.6.6+dfsg-3
7.6.12+dfsg-1
7.6.12+dfsg-2
7.6.15+dfsg-1
7.6.17+dfsg-1
7.6.17+dfsg-1ubuntu1
7.6.17+dfsg-1ubuntu2
7.6.20+dfsg-4
7.6.21+dfsg-1
7.6.22+dfsg-1
7.6.22+dfsg-2
7.6.22+dfsg-3
7.6.23+dfsg-1
7.6.25+dfsg-1
7.6.25+dfsg-2
7.6.28+dfsg-1
7.6.31+dfsg-5
7.6.31+dfsg-6
7.6.31+dfsg-6ubuntu1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000875.json"

Ubuntu:Pro:18.04:LTS / boinc

Package

Name
boinc
Purl
pkg:deb/ubuntu/boinc@7.9.3+dfsg-5ubuntu2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.8.3+dfsg-1
7.8.3+dfsg-2
7.8.4+dfsg-1
7.8.6+dfsg-1
7.8.6+dfsg-2
7.8.6+dfsg-3
7.9.1+dfsg-1
7.9.2+dfsg-1
7.9.2+dfsg-1build1
7.9.3+dfsg-1
7.9.3+dfsg-2~build2
7.9.3+dfsg-2
7.9.3+dfsg-3
7.9.3+dfsg-4
7.9.3+dfsg-5
7.9.3+dfsg-5ubuntu1
7.9.3+dfsg-5ubuntu2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000875.json"

Ubuntu:Pro:20.04:LTS / boinc

Package

Name
boinc
Purl
pkg:deb/ubuntu/boinc@7.16.6+dfsg-1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.16.3+dfsg-1
7.16.4+dfsg-1
7.16.5+dfsg-1
7.16.6+dfsg-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000875.json"