CVE-2018-18585: Null Pointer Dereference
Published Oct 23, 2018
·Updated
chmdreadheaders in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
Affected Software
22 affected componentsFixes available
redhat/libmspack<0.8
0.8
redhat/cabextract<1.8
1.8
debian/libmspack
0.10.1-20.11-10.11-1.1
Kyzer Libmspack=0.3-alpha
Kyzer Libmspack=0.4-alpha
Kyzer Libmspack=0.5-alpha
Kyzer Libmspack=0.6-alpha
Kyzer Libmspack=0.7-alpha
Debian Debian Linux=8.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server=12-ga
SUSE Linux Enterprise Server=12-sp1
SUSE Linux Enterprise Server=12-sp2
Starwindsoftware Starwind Virtual San Vsphere
Remediation
Patch Available
Event History
Oct 23, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:57 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·06:12 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2018-18585?
CVE-2018-18585 is a vulnerability in the chmd_read_headers function in libmspack before version 0.8alpha.
2
What is the severity of CVE-2018-18585?
The severity of CVE-2018-18585 is medium, with a CVSS score of 4.3.
3
Which software packages are affected by CVE-2018-18585?
The affected software packages are libmspack before 0.8alpha and clamav.
4
How can I fix CVE-2018-18585 for libmspack?
To fix CVE-2018-18585 for libmspack, update to version 0.8alpha or later.
5
How can I fix CVE-2018-18585 for clamav?
To fix CVE-2018-18585 for clamav, update to version 0.100.2+dfsg-1ubuntu0.14.04.2 or later.