Unrated severityNVD Advisory· Published Oct 23, 2018· Updated Aug 5, 2024
CVE-2018-18584
CVE-2018-18584
Description
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
Affected products
7- osv-coords7 versionspkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 0.6-3.3.11+ 6 more
- (no CPE)range: < 0.6-3.3.11
- (no CPE)range: < 0.0.20060920alpha-74.11.6.1
- (no CPE)range: < 0.4-15.7.1
- (no CPE)range: < 0.0.20060920alpha-74.11.6.1
- (no CPE)range: < 0.4-15.7.1
- (no CPE)range: < 0.0.20060920alpha-74.11.6.1
- (no CPE)range: < 0.4-15.7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- access.redhat.com/errata/RHSA-2019:2049mitrevendor-advisory
- security.gentoo.org/glsa/201903-20mitrevendor-advisory
- usn.ubuntu.com/3814-1/mitrevendor-advisory
- usn.ubuntu.com/3814-2/mitrevendor-advisory
- usn.ubuntu.com/3814-3/mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2018/10/msg00017.htmlmitremailing-list
- bugs.debian.org/911640mitre
- github.com/kyz/libmspack/commit/40ef1b4093d77ad3a5cfcee1f5cb6108b3a3bcc2mitre
- www.cabextract.org.ukmitre
- www.openwall.com/lists/oss-security/2018/10/22/1mitre
- www.starwindsoftware.com/security/sw-20181213-0001/mitre
News mentions
0No linked articles in our index yet.