{"id":"CVE-2018-0493","details":"remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.","modified":"2026-07-08T05:50:09.532342052Z","published":"2018-04-03T07:29:00.283Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"references":[{"type":"WEB","url":"https://git.eyrie.org/?p=kerberos/remctl.git%3Ba=commit%3Bh=86c7e44090c988112a37589d2c7a94029eb5e641"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4159"},{"type":"ADVISORY","url":"https://www.eyrie.org/~eagle/software/remctl/security/2018-04-01.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rra/remctl","events":[{"introduced":"0"},{"fixed":"ea426fbf4800ff010b354d247fd185fd6a686d6d"}],"database_specific":{"cpe":"cpe:2.3:a:eyrie:remctl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.14"}],"source":"CPE_RANGE"}}],"versions":["upstream/3.13","upstream/3.12","upstream/3.11","upstream/3.10","upstream/3.9","upstream/3.8","upstream/3.7","upstream/3.6","upstream/3.5","upstream/3.4","upstream/3.3","upstream/3.2","upstream/3.1","upstream/3.0","upstream/2.18","upstream/2.17","upstream/2.16","upstream/2.15","upstream/2.14","upstream/2.13","release/2.12","debian/2.12-1","debian/2.11-3","debian/2.11-2","debian/2.11-1","release/2.11","debian/2.10-1","release/2.10","debian/2.9-1","release/2.9","debian/2.8-1","release/2.8","debian/2.7-2","debian/2.7-1","release/2.7","debian/2.6-2","debian/2.6-1","release/2.2","debian/2.2-1","release/2.6","release/2.5","debian/2.5-1","release/2.4","debian/2.4-1","debian/2.3-1","release/2.3","debian/2.1-1","release/2.1","debian/2.0-2","release/2.0","debian/2.0-1","debian/1.12-2","debian/1.12-1","release/1.12","release/1.11","debian/1.11-1","debian/1.10-1","release/1.10","release/1.9","debian/1.9-1","debian/1.8-2","debian/1.8-1","release/1.8","debian/1.7-2","release/1.7","release/1.6","release/1.5","release/1.4","release/1.3","release/1.2.1","release/1.2","release/1.1","release/1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-0493.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}