Improper input validation in libmspack - CVE-2018-14680

 

Improper input validation in libmspack - CVE-2018-14680

Published: August 1, 2018


Vulnerability identifier: #VU14161
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14680
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists due to the chmd_read_headers() function, as defined in the mspack/chmd.c source code file of the affected software, does not reject blank CHM filenames. A local attacker can submit a CHM file with a blank filename and cause the service to crash.


Affected software

libmspack
Debian Linux
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
libmspack (Alpine package)
clamav (Alpine package)
libmspack
clamav
cabextract
ClamAV

How to mitigate CVE-2018-14680

Update to version 0.7.

libmspack - update to 0.7
libmspack (Alpine package) - update to 0.7.1_alpha-r0
clamav (Alpine package) - update to 0.100.2-r0
libmspack - addressed in versions 0.7-0.1.alpha.el7, 0.9.1-0.1.alpha.fc27, 0.9.1-0.1.alpha.fc28, 0.9.1-0.1.alpha.fc29
clamav - addressed in versions 0.100.2-1.el6, 0.100.2-2.el7, 0.100.2-2.fc27, 0.100.2-2.fc28, 0.100.2-2.fc29
cabextract - addressed in versions 1.9-1.fc27, 1.9-1.fc28, 1.9-1.fc29

External References

Related Security Bulletins