First published: Mon Oct 22 2018(Updated: )
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libmspack | <0.8 | 0.8 |
redhat/cabextract | <1.8 | 1.8 |
Cabextract Project Cabextract | <1.8 | |
Libmspack Project Libmspack | =0.3-alpha | |
Libmspack Project Libmspack | =0.4-alpha | |
Libmspack Project Libmspack | =0.5-alpha | |
Libmspack Project Libmspack | =0.6-alpha | |
Libmspack Project Libmspack | =0.7-alpha | |
Libmspack Project Libmspack | =0.7.1-alpha | |
Debian Debian Linux | =8.0 | |
Redhat Enterprise Linux | =7.0 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =12-ga | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE Linux Enterprise Server | =12-sp2 | |
Starwindsoftware Starwind Virtual San Vsphere | ||
ubuntu/cabextract | <1.4-4ubuntu0.1~ | 1.4-4ubuntu0.1~ |
ubuntu/cabextract | <1.4-5 | 1.4-5 |
ubuntu/clamav | <0.100.2+dfsg-1ubuntu0.14.04.2 | 0.100.2+dfsg-1ubuntu0.14.04.2 |
ubuntu/libmspack | <0.6-3ubuntu0.2 | 0.6-3ubuntu0.2 |
ubuntu/libmspack | <0.7-1ubuntu0.1 | 0.7-1ubuntu0.1 |
ubuntu/libmspack | <0.4-1ubuntu0.1~ | 0.4-1ubuntu0.1~ |
ubuntu/libmspack | <0.5-1ubuntu0.16.04.3 | 0.5-1ubuntu0.16.04.3 |
debian/cabextract | 1.9-3 1.11-2 | |
debian/libmspack | 0.10.1-2 0.11-1 0.11-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-18584.
The severity of CVE-2018-18584 is medium (6.5).
The affected software for CVE-2018-18584 includes cabextract before version 1.8 and libmspack before version 0.8alpha.
To fix CVE-2018-18584, you should update cabextract to version 1.8 or later, and libmspack to version 0.8alpha or later.
More information about CVE-2018-18584 can be found at the following references: [link1](https://bugs.debian.org/911640), [link2](https://github.com/kyz/libmspack/commit/40ef1b4093d77ad3a5cfcee1f5cb6108b3a3bcc2), and [link3](https://www.cabextract.org.uk/#changes).