Stack-based buffer overflow in librelp - CVE-2018-1000140

 

Stack-based buffer overflow in librelp - CVE-2018-1000140

Published: March 28, 2018


Vulnerability identifier: #VU11306
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000140
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to execute arbitrary code on the target system.

The weakness exists in the relpTcpChkPeerName function due to insufficient validation of X.509 certificates and improper checks on the return value. A remote attacker can send a specially crafted X.509 certificate, trigger stack-based buffer overflow and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

librelp
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux EUS Compute Node
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Fedora
librelp
librelp-debugsource
librelp0
librelp0-debuginfo
librelp-devel

How to mitigate CVE-2018-1000140

Update to version 1.2.15.

librelp - addressed in versions 1.2.15-1.fc26, 1.2.15-1.fc27
librelp-debugsource - update to 1.2.15-3.6.3
librelp0 - update to 1.2.15-3.6.3
librelp0-debuginfo - update to 1.2.15-3.6.3
librelp-devel - update to 1.2.15-3.6.3

External References

Related Security Bulletins