UBUNTU-CVE-2018-1000875
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1000875
Summary:
Details: Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account. This attack appear to be exploitable via Specially crafted URL. This vulnerability appears to have been fixed in 1.0.3.
References: https://ubuntu.com/security/CVE-2018-1000875, https://github.com/BOINC/boinc/issues/2907, https://www.cve.org/CVERecord?id=CVE-2018-1000875
Affected packages
Package
Name: boinc
Purl: pkg:deb/ubuntu/[email protected]+dfsg-6ubuntu1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
7.6.6+dfsg-3
7.6.12+dfsg-1
7.6.12+dfsg-2
7.6.15+dfsg-1
7.6.17+dfsg-1
7.6.17+dfsg-1ubuntu1
7.6.17+dfsg-1ubuntu2
7.6.20+dfsg-4
7.6.21+dfsg-1
7.6.22+dfsg-1
7.6.22+dfsg-2
7.6.22+dfsg-3
7.6.23+dfsg-1
7.6.25+dfsg-1
7.6.25+dfsg-2
7.6.28+dfsg-1
7.6.31+dfsg-5
7.6.31+dfsg-6
7.6.31+dfsg-6ubuntu1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
