Memory corruption in unixODBC - CVE-2018-7485

 

Memory corruption in unixODBC - CVE-2018-7485

Published: March 20, 2018


Vulnerability identifier: #VU11172
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7485
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists in the SQLWriteFileDSN function due to boundary error. A remote attacker can trigger memory corruption and cause the service to crash.

Affected software

unixODBC
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - TUS
Fedora
openSUSE Leap
unixODBC (Red Hat package)
unixODBC

How to mitigate CVE-2018-7485

Install update from vendor's website.

unixODBC (Red Hat package) - update to 2.3.1-14.el7_6
unixODBC - addressed in versions 2.3.7-1.fc27, 2.3.7-1.fc28

External References

Related Security Bulletins