Stack-based buffer overflow in libmspack - CVE-2018-14681

 

Stack-based buffer overflow in libmspack - CVE-2018-14681

Published: July 31, 2018 / Updated: August 1, 2018


Vulnerability identifier: #VU14159
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14681
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to stack-based buffer overflow in the kwajd_read_headers function, as defined in the mspack/kwajd.c source code file. A local attacker can send a specially crafted request that submits malicious input, trigger memory corruption and cause the service to crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

libmspack
Gentoo Linux
Amazon Linux AMI
Debian Linux
SUSE MicroOS
Fedora
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
Opensuse
SUSE Linux Enterprise Module for Basesystem
libmspack (Alpine package)
clamav (Alpine package)
libmspack-debugsource
libmspack-devel
libmspack0
libmspack0-debuginfo
libmspack
clamav
cabextract
ClamAV

How to mitigate CVE-2018-14681

Update to version 0.7.

libmspack - update to 0.7
libmspack (Alpine package) - update to 0.7.1_alpha-r0
clamav (Alpine package) - update to 0.100.2-r0
libmspack-debugsource - addressed in versions 0.4-15.10.1, 0.6-3.11.1
libmspack-devel - addressed in versions 0.4-15.10.1, 0.6-3.11.1
libmspack0 - addressed in versions 0.4-15.10.1, 0.6-3.11.1
libmspack0-debuginfo - addressed in versions 0.4-15.10.1, 0.6-3.11.1
libmspack - addressed in versions 0.7-0.1.alpha.fc27, 0.7-0.1.alpha.fc28, 0.9.1-0.1.alpha.fc27, 0.9.1-0.1.alpha.fc28, 0.9.1-0.1.alpha.fc29
clamav - addressed in versions 0.100.2-1.el6, 0.100.2-2.el7, 0.100.2-2.fc27, 0.100.2-2.fc28, 0.100.2-2.fc29
cabextract - addressed in versions 1.9-1.fc27, 1.9-1.fc28, 1.9-1.fc29

External References

Related Security Bulletins