First published: Sat Jul 28 2018(Updated: )
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libmspack | <0.7 | 0.7 |
debian/libmspack | 0.10.1-2 0.11-1 0.11-1.1 | |
cabextract and libmspack | =0.0.20060920-alpha | |
cabextract and libmspack | =0.3-alpha | |
cabextract and libmspack | =0.4-alpha | |
cabextract and libmspack | =0.5-alpha | |
cabextract and libmspack | =0.6-alpha | |
cabextract and libmspack | <=1.5 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
redhat ansible tower | =3.3 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-14682.
The severity of CVE-2018-14682 is high, with a CVSS score of 8.8.
The affected software for CVE-2018-14682 is libmspack before version 0.7alpha.
To fix CVE-2018-14682, it is recommended to update libmspack to version 0.7 or later.
You can find more information about CVE-2018-14682 on the following references: (1) http://www.openwall.com/lists/oss-security/2018/07/26/1, (2) http://www.securitytracker.com/id/1041410, (3) https://access.redhat.com/errata/RHSA-2018:3327