MEDIUM
libmspack: Out-of-bounds write in mspack/cab.h
Published Oct 23, 2018
6.5
MEDIUMCVSS 3.1
EPSS 3.09%
Description
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
Affected products
No data.
Configuration 1
OR
- < 1.8
- 0.3
- 0.4
- 0.5
- 0.6
- 0.7
- 0.7.1
Configuration 2
- 8.0
Configuration 3
- 7.0
Configuration 4
OR
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 5
OR
- 11
- 12
- 12
- 12
Configuration 6
- n/a
No data.
Red Hat Enterprise Linux 7
libmspack-0:0.5-0.7.alpha.el7
Fixed · RHSA-2019:2049
Red Hat Enterprise Linux 8
libmspack
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libmspack-0:0.5-0.7.alpha.el7 | Fixed | RHSA-2019:2049 |
| Red Hat Enterprise Linux 8 | libmspack | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of libmspack as shipped with Red Hat Enterprise Linux 7.
Weaknesses (1)
References (15)
- https://access.redhat.com/errata/RHSA-2019:2049 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-18584 Vendor Advisory
- https://bugs.debian.org/911640 Mailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1644214 Issue Tracking
- https://github.com/kyz/libmspack/commit/40ef1b4093d77ad3a5cfcee1f5cb6108b3a3bcc2 PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00017.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-18584
- https://security.gentoo.org/glsa/201903-20 vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/3814-1/ vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/3814-2/ vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/3814-3/ vendor-advisoryThird Party Advisory
- https://www.cabextract.org.uk/#changes ProductVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-18584
- https://www.openwall.com/lists/oss-security/2018/10/22/1 Mailing ListThird Party Advisory
- https://www.starwindsoftware.com/security/sw-20181213-0001/ Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 23, 2018
Updated Aug 5, 2024
Reserved Oct 22, 2018
Link CVE-2018-18584
CISA Vulnrichment
Updated n/a