UBUNTU-CVE-2018-6758

Source
https://ubuntu.com/security/CVE-2018-6758
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-6758.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-6758
Upstream
Published
2018-02-06T18:29:00Z
Modified
2025-09-08T16:44:46Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The uwsgiexpandpath function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a large directory length.

References

Affected packages

Ubuntu:14.04:LTS / uwsgi

Package

Name
uwsgi
Purl
pkg:deb/ubuntu/uwsgi@1.9.17.1-5ubuntu0.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.17.1-5ubuntu0.1

Affected versions

1.*

1.9.13-4build1
1.9.17.1-5
1.9.17.1-5build2
1.9.17.1-5build4
1.9.17.1-5build5

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libapache2-mod-proxy-uwsgi",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "libapache2-mod-ruwsgi",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "libapache2-mod-uwsgi",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "python-uwsgidecorators",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "python3-uwsgidecorators",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-app-integration-plugins",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-core",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-emperor",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-extra",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-infrastructure-plugins",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-alarm-curl",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-alarm-xmpp",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-curl-cron",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-emperor-pg",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-erlang",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-fiber",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-geoip",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-graylog2",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-greenlet-python",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-jvm-openjdk-6",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-jvm-openjdk-7",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-jwsgi-openjdk-6",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-jwsgi-openjdk-7",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-ldap",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-lua5.1",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-lua5.2",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-php",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-psgi",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-pyerl-python",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-pyerl-python3",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-python",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-python3",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-rack-ruby1.9.1",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-rbthreads",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-router-access",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-sqlite3",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-v8",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugin-xslt",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        },
        {
            "binary_name": "uwsgi-plugins-all",
            "binary_version": "1.9.17.1-5ubuntu0.1"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-6758.json"

Ubuntu:16.04:LTS / uwsgi

Package

Name
uwsgi
Purl
pkg:deb/ubuntu/uwsgi@2.0.12-5ubuntu3.2?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.12-5ubuntu3.2

Affected versions

2.*

2.0.7-1ubuntu5
2.0.7-1ubuntu6
2.0.11.2-6ubuntu1
2.0.11.2-6ubuntu2
2.0.12-4ubuntu2
2.0.12-5ubuntu1
2.0.12-5ubuntu2
2.0.12-5ubuntu3
2.0.12-5ubuntu3.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libapache2-mod-proxy-uwsgi",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "libapache2-mod-ruwsgi",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "libapache2-mod-uwsgi",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "python-uwsgidecorators",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "python3-uwsgidecorators",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-app-integration-plugins",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-core",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-emperor",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-extra",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-infrastructure-plugins",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-alarm-curl",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-alarm-xmpp",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-asyncio-python",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-asyncio-python3",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-curl-cron",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-emperor-pg",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-fiber",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-gccgo",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-geoip",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-gevent-python",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-glusterfs",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-graylog2",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-greenlet-python",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-jvm-openjdk-8",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-jwsgi-openjdk-8",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-ldap",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-lua5.1",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-lua5.2",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-luajit",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-mono",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-php",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-psgi",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-python",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-python3",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-rack-ruby2.3",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-rados",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-rbthreads",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-ring-openjdk-8",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-router-access",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-servlet-openjdk-8",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-sqlite3",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-tornado-python",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-v8",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugin-xslt",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-plugins-all",
            "binary_version": "2.0.12-5ubuntu3.2"
        },
        {
            "binary_name": "uwsgi-src",
            "binary_version": "2.0.12-5ubuntu3.2"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-6758.json"