Memory corruption in unixODBC - CVE-2018-7485
Published: March 20, 2018
Vulnerability identifier: #VU11172
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7485
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists in the SQLWriteFileDSN function due to boundary error. A remote attacker can trigger memory corruption and cause the service to crash.
The weakness exists in the SQLWriteFileDSN function due to boundary error. A remote attacker can trigger memory corruption and cause the service to crash.
Affected software
unixODBC
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - TUS
Fedora
openSUSE Leap
unixODBC (Red Hat package)
unixODBC
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - TUS
Fedora
openSUSE Leap
unixODBC (Red Hat package)
unixODBC
How to mitigate CVE-2018-7485
Install update from vendor's website.
unixODBC (Red Hat package) - update to 2.3.1-14.el7_6
unixODBC - addressed in versions 2.3.7-1.fc27, 2.3.7-1.fc28
unixODBC - addressed in versions 2.3.7-1.fc27, 2.3.7-1.fc28