Out-of-bounds write in libmspack - CVE-2018-18584
Published: October 24, 2018 / Updated: October 25, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.
The vulnerability exists in the mspack/cab.h source code file due to Microsoft cabinet file (CAB) with a Quantum-compressed block of exactly 38,912 B will write 1 B beyond the end of the input buffer. when handling malicious input. A remote unauthenticated attacker can trick the victim into accessing of a CAB file that submits malicious input to the targeted system, trigger an out-of-bounds write condition and cause the application to crash or execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
libmspack (Alpine package)
cabextract (Alpine package)
libmspack
cabextract
cabextract
How to mitigate CVE-2018-18584
libmspack (Alpine package) - addressed in versions 0.8_alpha-r0, 0.8_alpha-r1
cabextract - update to 1.8
cabextract (Alpine package) - update to 1.9-r0
libmspack - addressed in versions 0.5-0.0.7.alpha.el7, 0.9.1-0.1.alpha.fc27, 0.9.1-0.1.alpha.fc28, 0.9.1-0.1.alpha.fc29
cabextract - addressed in versions 1.9-1.fc27, 1.9-1.fc28, 1.9-1.fc29, 1.9-7.el7
External References
Related Security Bulletins
- Remote code execution in libmspack
- Remote code execution in cabextract
- Red Hat update for libmspack
- Out-of-bounds write in libmspack (Alpine package)
- Out-of-bounds write in cabextract (Alpine package)
- Gentoo update for cabextract, libmspack
- Fedora EPEL 7 update for cabextract
- Fedora 29 update for cabextract, libmspack
- Fedora 28 update for cabextract, libmspack
- Fedora 27 update for cabextract, libmspack
- Fedora EPEL 7 update for libmspack