CVE-2018-14682: High severity cabextract and libmspack vulnerability
Published Jul 28, 2018
·Updated
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
Affected Software
18 affected componentsFixes available
redhat/libmspack<0.7
0.7
debian/libmspack
0.10.1-20.11-10.11-1.1
Cabextract Libmspack=0.0.20060920-alpha
Cabextract Libmspack=0.3-alpha
Cabextract Libmspack=0.4-alpha
Cabextract Libmspack=0.5-alpha
Cabextract Libmspack=0.6-alpha
Cabextract Project Cabextract<=1.5
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
redhat Ansible Tower=3.3
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Remediation
Patch Available
Event History
Jul 28, 2018
Data Sourced
07:33 AM
SeverityAffected Software
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:52 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:58 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-14682.
2
What is the severity of CVE-2018-14682?
The severity of CVE-2018-14682 is high, with a CVSS score of 8.8.
3
What is the affected software for CVE-2018-14682?
The affected software for CVE-2018-14682 is libmspack before version 0.7alpha.
4
How can I fix CVE-2018-14682?
To fix CVE-2018-14682, it is recommended to update libmspack to version 0.7 or later.
5
Where can I find more information about CVE-2018-14682?
You can find more information about CVE-2018-14682 on the following references: (1) http://www.openwall.com/lists/oss-security/2018/07/26/1, (2) http://www.securitytracker.com/id/1041410, (3) https://access.redhat.com/errata/RHSA-2018:3327