CVE-2018-14680: Input Validation
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. ...
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-14680?
CVE-2018-14680 is a vulnerability in libmspack before version 0.7alpha that allows empty CHM filenames.
How severe is CVE-2018-14680?
CVE-2018-14680 has a severity rating of 6.5 (high).
Which software is affected by CVE-2018-14680?
CVE-2018-14680 affects Ubuntu's clamav package (version 0.100.1+dfsg-1ubuntu0.14.04.3), libmspack packages for Ubuntu (versions up to 0.6-3ubuntu0.1 and version 0.7), and Cabextract Libmspack packages (versions 0.0.20060920-alpha, 0.3-alpha, 0.4-alpha, 0.5-alpha, and 0.6-alpha).
Is there a fix for CVE-2018-14680?
Yes, there are fixes available for CVE-2018-14680. For Ubuntu, update the affected packages to the specified remedial versions. For Cabextract Libmspack, update to version 0.7.
Where can I find more information about CVE-2018-14680?
You can find more information about CVE-2018-14680 at the following sources: [Openwall](http://www.openwall.com/lists/oss-security/2018/07/26/1), [Security Tracker](http://www.securitytracker.com/id/1041410), and [Red Hat](https://access.redhat.com/errata/RHSA-2018:3327).