CVE-2018-18584: Medium severity Cabextract Project Cabextract vulnerability
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-18584.
What is the severity of CVE-2018-18584?
The severity of CVE-2018-18584 is medium (6.5).
What is the affected software for CVE-2018-18584?
The affected software for CVE-2018-18584 includes cabextract before version 1.8 and libmspack before version 0.8alpha.
How do I fix CVE-2018-18584?
To fix CVE-2018-18584, you should update cabextract to version 1.8 or later, and libmspack to version 0.8alpha or later.
Where can I find more information about CVE-2018-18584?
More information about CVE-2018-18584 can be found at the following references: [link1](https://bugs.debian.org/911640), [link2](https://github.com/kyz/libmspack/commit/40ef1b4093d77ad3a5cfcee1f5cb6108b3a3bcc2), and [link3](https://www.cabextract.org.uk/#changes).