Stack-based buffer overflow in libmspack - CVE-2018-14679
Published: August 1, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to stack-based buffer overflow the read_chunk function, as defined in the mspack/chmd.c source code file. A local attacker can send a specially crafted request that submits malicious input, trigger memory corruption and cause the service to crash.
Affected software
Gentoo Linux
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Linux Enterprise Micro
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
SUSE Enterprise Storage
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for Power
SUSE Linux Enterprise Server
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Basesystem
Basesystem Module
openSUSE Leap
Opensuse
libmspack (Alpine package)
libmspack-debugsource
libmspack0
libmspack0-debuginfo
libmspack-devel
libmspack
clamav
clamav-debugsource
clamav-debuginfo
clamav-openssl1
clamav-devel
clamav-docs-html
libfreshclam3-debuginfo
libclammspack0
clamav-milter-debuginfo
libfreshclam3
libclamav12
libclammspack0-debuginfo
clamav-milter
libclamav12-debuginfo
ClamAV
RSA Authentication Manager
How to mitigate CVE-2018-14679
libmspack (Alpine package) - update to 0.7.1_alpha-r0
RSA Authentication Manager - update to 8.7 SP2 Patch 6
libmspack-debugsource - update to 0.6-3.11.1
libmspack0 - update to 0.6-3.11.1
libmspack0-debuginfo - update to 0.6-3.11.1
libmspack-devel - update to 0.6-3.11.1
libmspack - addressed in versions 0.7-0.1.alpha.el7, 0.7-0.1.alpha.fc27, 0.7-0.1.alpha.fc28
clamav - addressed in versions 0.100.2-1.el6, 0.100.2-2.el7, 0.100.2-2.fc27, 0.100.2-2.fc28, 0.100.2-2.fc29
clamav-debugsource - addressed in versions 0.103.4-0.20.41.1, 0.103.4-3.12.1, 0.103.4-33.41.1, 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
clamav-debuginfo - addressed in versions 0.103.4-0.20.41.1, 0.103.4-3.12.1, 0.103.4-33.41.1, 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
clamav-openssl1 - update to 0.103.4-0.20.41.1
clamav - addressed in versions 0.103.4-0.20.41.1, 0.103.4-3.12.1, 0.103.4-33.41.1, 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
clamav-devel - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
clamav-docs-html - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
libfreshclam3-debuginfo - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
libclammspack0 - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
clamav-milter-debuginfo - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
libfreshclam3 - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
libclamav12 - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
libclammspack0-debuginfo - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
clamav-milter - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
libclamav12-debuginfo - addressed in versions 1.4.2-3.36.1, 1.4.2-150200.8.3.1, 1.4.2-150600.18.6.1
External References
Related Security Bulletins
- Multiple vulnerabilities in libmspack
- Debian update for libmspack
- Multiple vulnerabilities in Clam AntiVirus
- OpenSUSE Linux update for clamav
- Amazon Linux AMI update for clamav
- Red Hat update for libmspack
- Stack-based buffer overflow in libmspack (Alpine package)
- Gentoo update for cabextract, libmspack
- SUSE update for libmspack
- SUSE update for clamav
- SUSE update for clamav
- SUSE update for clamav
- SUSE update for clamav
- SUSE update for clamav
- SUSE update for clamav
- Fedora 28 update for libmspack
- Fedora 27 update for libmspack
- Fedora EPEL 7 update for libmspack
- Fedora 29 update for clamav
- Fedora 28 update for clamav
- Fedora 27 update for clamav
- Fedora EPEL 7 update for clamav
- Fedora EPEL 6 update for clamav
- RSA Authentication Manager update for third-party components