Fedora

Fedora Linux 18 (Spherical Cow)

Fedora Linux 18 (Spherical Cow)

The Fedora Linux 18 (Spherical Cow) reached end of service life on Jan 14, 2014 — Fedora no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.

End of Service LifeEOSL Date: Jan 14, 2014
Issue Management

24/7 engineers own your Fedora Linux 18 (Spherical Cow) incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
fedora
release
18
product Label
Fedora Linux
release Label
18 (Spherical Cow)
codename
Spherical Cow
lts
latest Version
release Date
2013-01-15
maintained
source Url
https://endoflife.date/fedora

Lifecycle Dates

End of Service Life
Jan 14, 2014
Last OEM Support
Jan 14, 2014

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Fedora Linux 18 (Spherical Cow) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Fedora Linux 18 (Spherical Cow)?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Fedora Linux 18 (Spherical Cow) when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Fedora Linux 18 (Spherical Cow) Support: Frequently Asked Questions

Is the Fedora Linux 18 (Spherical Cow) still supported?

Fedora ended support for the Fedora Linux 18 (Spherical Cow) on Jan 14, 2014 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.

When is the Fedora Linux 18 (Spherical Cow) end of service life (EOSL) date?

Fedora lists the end of service life for the Fedora Linux 18 (Spherical Cow) as Jan 14, 2014.

Can I keep using the Fedora Linux 18 (Spherical Cow) after its EOSL date?

Yes. EOSL means Fedora stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Fedora Linux 18 (Spherical Cow) cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Fedora Linux 18 (Spherical Cow)

95 published CVEs affect the Fedora Linux 18 (Spherical Cow), including 37 rated critical or high severity. Fedora no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.

CVESeverityCVSSPublishedSummary
CVE-2013-1437CRITICAL9.8Jan 28, 2020Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
CVE-2013-7088CRITICAL9.8Nov 15, 2019ClamAV before 0.97.7 has buffer overflow in the libclamav component
CVE-2013-7087CRITICAL9.8Nov 15, 2019ClamAV before 0.97.7 has WWPack corrupt heap memory
CVE-2013-4409CRITICAL9.8Nov 4, 2019An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
CVE-2019-11235CRITICAL9.8Apr 22, 2019FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
CVE-2019-11234CRITICAL9.8Apr 22, 2019FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
CVE-2013-6671CRITICAL9.8Dec 11, 2013The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.
CVE-2013-5618CRITICAL9.8Dec 11, 2013Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.
CVE-2013-5616CRITICAL9.8Dec 11, 2013Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listeners.
CVE-2013-5615CRITICAL9.8Dec 11, 2013The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors.
CVE-2013-5613CRITICAL9.8Dec 11, 2013Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.
CVE-2013-5609CRITICAL9.8Dec 11, 2013Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2012-3363CRITICAL9.1Feb 13, 2013Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
CVE-2013-5610HIGH10.0Dec 11, 2013Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2012-6075HIGH9.3Feb 13, 2013Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
CVE-2019-10132HIGH8.8May 22, 2019A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
CVE-2013-4751HIGH8.1Nov 1, 2019php-symfony2-Validator has loss of information during serialization
CVE-2013-4161HIGH7.8Dec 31, 2019gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.
CVE-2012-4480HIGH7.8Dec 2, 2019mom creates world-writable pid files in /var/run
CVE-2012-5617HIGH7.8Nov 25, 2019gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation

Showing the 20 most severe of 95 known CVEs.

Get Third Party Support

Related Fedora Products

All Fedora products →
Fedora Linux 18 (Spherical Cow)
Save 40-70% vs OEM
Get Third Party Support