GLIBC as used by IBM QRadar Network Packet Capture is vulnerable to a buffer overflow
CVEID: CVE-2018-11237
**Description:**GNU glibc is vulnerable to a buffer overflow, caused by improper bounds of checking by the mempcpy function. By sending a specially-crafted request, a remote attacker could overflow a buffer and execute arbitrary code on the system.
**CVSS Base Score:**7.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/143580> for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
IBM Security QRadar Packet Capture 7.2.0 - 7.2.8 Patch 2
IBM Security QRadar Packet Capture 7.3.0 - 7.3.1 Patch 2
QRadar Network Packet Capture 7.2.8 Patch 3
QRadar Network Packet Capture 7.3.2 GA
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm security qradar siem | eq | 7.2 | |
ibm security qradar siem | eq | 7.3 |