Null pointer dereference in libmspack - CVE-2018-18585

 

Null pointer dereference in libmspack - CVE-2018-18585

Published: November 14, 2018 / Updated: November 15, 2018


Vulnerability identifier: #VU15908
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-18585
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to  the chmd_read_headers function, as defined in the mspack/chmd.c source code file of the affected software, accepts filenames that have embedded NULL bytes. A remote attacker can trick the victim into accessing a Compiled HTML (CHM) file that submits malicious input to the targeted system, trigger NULL pointer dereference and cause the service to crash.


Affected software

libmspack
Gentoo Linux
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
libmspack (Alpine package)
libmspack
cabextract

How to mitigate CVE-2018-18585

Update to version 0.8alpha.

libmspack - update to 0.8alpha
libmspack (Alpine package) - addressed in versions 0.8_alpha-r0, 0.8_alpha-r1
libmspack - addressed in versions 0.5-0.0.7.alpha.el7, 0.9.1-0.1.alpha.fc27, 0.9.1-0.1.alpha.fc28, 0.9.1-0.1.alpha.fc29
cabextract - addressed in versions 1.9-1.fc27, 1.9-1.fc28, 1.9-1.fc29, 1.9-7.el7

External References

Related Security Bulletins