Buffer overflow in unixODBC - CVE-2018-7409
Published: March 26, 2018
Vulnerability identifier: #VU11274
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7409
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition or execute arbitrary code on the target system.
The weakness exists in the unicode_to_ansi_copy() function due to buffer overflow. A remote attacker can send specially crafted input, cause the service to crash or execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the unicode_to_ansi_copy() function due to buffer overflow. A remote attacker can send specially crafted input, cause the service to crash or execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
unixODBC
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - TUS
Ubuntu
Fedora
openSUSE Leap
libodbc1 (Ubuntu package)
unixodbc (Ubuntu package)
unixODBC (Red Hat package)
unixODBC
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - TUS
Ubuntu
Fedora
openSUSE Leap
libodbc1 (Ubuntu package)
unixodbc (Ubuntu package)
unixODBC (Red Hat package)
unixODBC
How to mitigate CVE-2018-7409
Update to version 2.3.5.
libodbc1 (Ubuntu package) - update to Ubuntu Pro
unixodbc (Ubuntu package) - update to Ubuntu Pro
unixODBC (Red Hat package) - update to 2.3.1-14.el7_6
unixODBC - addressed in versions 2.3.7-1.fc27, 2.3.7-1.fc28
unixodbc (Ubuntu package) - update to Ubuntu Pro
unixODBC (Red Hat package) - update to 2.3.1-14.el7_6
unixODBC - addressed in versions 2.3.7-1.fc27, 2.3.7-1.fc28