CVE-2018-7409: Buffer Overflow
In unixODBC before 2.3.5, there is a buffer overflow in the unicodetoansicopy() function in DriverManager/info.c.
Other sources
unixODBC before version 2.3.5 is vulnerable to a buffer overflow in the DriverManager/info.c:unicodetoansicopy() method. An attacker could exploit this to cause a denial of service or other unspecified impact.
Upstream Release:
https://sourceforge.net/projects/unixodbc/files/unixODBC/2.3.5/
Upstream Revision:
https://sourceforge.net/p/unixodbc/code/136/#diff-12
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/unixodbcto a version that resolves this vulnerability.Fixed in 2.3.4-1.1ubuntu3 - Upgrade
Upgrade
ubuntu/unixodbcto a version that resolves this vulnerability.Fixed in 2.3.1-4.1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/unixodbcto a version that resolves this vulnerability.Fixed in 2.3.5 - Upgrade
Upgrade
ubuntu/unixodbcto a version that resolves this vulnerability.Fixed in 2.2.14 - Upgrade
Upgrade
debian/unixodbcto a version that resolves this vulnerability.Fixed in 2.3.6-0.1Fixed in 2.3.11-2+deb12u1Fixed in 2.3.12-1 - Upgrade
Upgrade
redhat/unixODBCto a version that resolves this vulnerability.Fixed in 2.3.5 - Upgrade
Upgrade
unixODBCto a version that resolves this vulnerability.Fixed in 2.3.5 - Compensating control
If you cannot upgrade immediately, mitigate the denial-of-service risk by restricting or rate-limiting access to the components that trigger unixODBC DriverManager/__info.c:unicode_to_ansi_copy().
Event History
Frequently Asked Questions
What is CVE-2018-7409?
CVE-2018-7409 is a vulnerability in unixODBC before version 2.3.5 that allows a buffer overflow in the unicode_to_ansi_copy() function.
What is the severity of CVE-2018-7409?
CVE-2018-7409 has a severity rating of 9.8 (Critical).
How does CVE-2018-7409 impact unixODBC?
CVE-2018-7409 affects unixODBC versions before 2.3.5 and could lead to a buffer overflow vulnerability.
How can I fix CVE-2018-7409?
To fix CVE-2018-7409, update unixODBC to version 2.3.5 or later.
Where can I find more information about CVE-2018-7409?
You can find more information about CVE-2018-7409 at the following references: [1] http://www.unixodbc.org/unixODBC-2.3.5.tar.gz, [2] https://sourceforge.net/projects/unixodbc/files/unixODBC/2.3.5/ChangeLog/download, [3] https://access.redhat.com/errata/RHSA-2019:2336