CVE-2018-14681: High severity cabextract and libmspack vulnerability
Published Jul 28, 2018
·Updated
An issue was discovered in kwajdreadheaders in mspack/kwajd.c in lib ...
Affected Software
18 affected componentsFixes available
redhat/libmspack<0.7
0.7
debian/libmspack
0.10.1-20.11-10.11-1.1
Cabextract Libmspack=0.0.20060920-alpha
Cabextract Libmspack=0.3-alpha
Cabextract Libmspack=0.4-alpha
Cabextract Libmspack=0.5-alpha
Cabextract Libmspack=0.6-alpha
Cabextract Project Cabextract<=1.5
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
redhat Ansible Tower=3.3
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Remediation
Patch Available
Event History
Jul 28, 2018
Data Sourced
via Debian·07:33 AM
SeverityAffected Software
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:52 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:58 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·12:18 AM
Description
Frequently Asked Questions
1
What is CVE-2018-14681?
CVE-2018-14681 is a vulnerability in libmspack before version 0.7alpha that can be exploited through bad KWAJ file header extensions, resulting in a one or two byte overwrite.
2
What is the severity of CVE-2018-14681?
The severity of CVE-2018-14681 is high, with a severity value of 8.8.
3
How does CVE-2018-14681 affect libmspack?
CVE-2018-14681 affects libmspack versions before 0.7alpha.
4
How can I fix CVE-2018-14681?
To fix CVE-2018-14681, upgrade to libmspack version 0.7alpha or later.
5
Where can I find more information about CVE-2018-14681?
More information about CVE-2018-14681 can be found at the following references: [1](http://www.openwall.com/lists/oss-security/2018/07/26/1), [2](http://www.securitytracker.com/id/1041410), [3](https://access.redhat.com/errata/RHSA-2018:3327)