Buffer overflow in unixODBC - CVE-2018-7409

 

Buffer overflow in unixODBC - CVE-2018-7409

Published: March 26, 2018


Vulnerability identifier: #VU11274
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7409
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition or execute arbitrary code on the target system.

The weakness exists in the unicode_to_ansi_copy() function due to buffer overflow. A remote attacker can send specially crafted input, cause the service to crash or execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

unixODBC
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - TUS
Ubuntu
Fedora
openSUSE Leap
libodbc1 (Ubuntu package)
unixodbc (Ubuntu package)
unixODBC (Red Hat package)
unixODBC

How to mitigate CVE-2018-7409

Update to version 2.3.5.

libodbc1 (Ubuntu package) - update to Ubuntu Pro
unixodbc (Ubuntu package) - update to Ubuntu Pro
unixODBC (Red Hat package) - update to 2.3.1-14.el7_6
unixODBC - addressed in versions 2.3.7-1.fc27, 2.3.7-1.fc28

External References

Related Security Bulletins