Stack-based buffer overflow in Libextractor - CVE-2018-14346
Published: October 14, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in ec_read_file_func() function in unzip.c. A remote attacker can create a specially crafted archive, trick the victim into opening it, trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
libextractor (Debian package)
extract (Ubuntu package)
libextractor-dev (Ubuntu package)
libextractor3 (Ubuntu package)
Ubuntu
How to mitigate CVE-2018-14346
libextractor (Debian package) - update to 1:1.3-4+deb9u2
extract (Ubuntu package) - update to 1:1.3-4+deb9u3build0.16.04.1
libextractor-dev (Ubuntu package) - update to 1:1.3-4+deb9u3build0.16.04.1
libextractor3 (Ubuntu package) - update to 1:1.3-4+deb9u3build0.16.04.1