/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2018-1330

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2018-1330

CGA ID

CGA-f35c-2pp6-7wwj

Severity

Unknown

Description

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

References

  • https://images.chainguard.dev/security/CGA-f35c-2pp6-7wwj

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs