Null pointer dereference in libmspack - CVE-2018-18585
Published: November 14, 2018 / Updated: November 15, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to the chmd_read_headers function, as defined in the mspack/chmd.c source code file of the affected software, accepts filenames that have embedded NULL bytes. A remote attacker can trick the victim into accessing a Compiled HTML (CHM) file that submits malicious input to the targeted system, trigger NULL pointer dereference and cause the service to crash.
Affected software
Gentoo Linux
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
libmspack (Alpine package)
libmspack
cabextract
How to mitigate CVE-2018-18585
libmspack (Alpine package) - addressed in versions 0.8_alpha-r0, 0.8_alpha-r1
libmspack - addressed in versions 0.5-0.0.7.alpha.el7, 0.9.1-0.1.alpha.fc27, 0.9.1-0.1.alpha.fc28, 0.9.1-0.1.alpha.fc29
cabextract - addressed in versions 1.9-1.fc27, 1.9-1.fc28, 1.9-1.fc29, 1.9-7.el7
External References
Related Security Bulletins
- Denial of service in libmspack
- Red Hat update for libmspack
- Null pointer dereference in libmspack (Alpine package)
- Gentoo update for cabextract, libmspack
- Fedora EPEL 7 update for cabextract
- Fedora 29 update for cabextract, libmspack
- Fedora 28 update for cabextract, libmspack
- Fedora 27 update for cabextract, libmspack
- Fedora EPEL 7 update for libmspack