CVE-2018-18585 Information

Description

chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has ‘\0’ as its first or second character (such as the /\0\ name).

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Reference

https://access.redhat.com/errata/RHSA-2019:2049 https://access.redhat.com/security/cve/cve-2018-18585 https://bugs.debian.org/911637 https://github.com/kyz/libmspack/commit/8759da8db6ec9e866cb8eb143313f397f925bb4f https://lists.debian.org/debian-lts-announce/2018/10/msg00017.html https://security.gentoo.org/glsa/201903-20 https://tools.cisco.com/security/center/viewAlert.x?alertId=59134 https://usn.ubuntu.com/3814-1/ https://usn.ubuntu.com/3814-2/ https://usn.ubuntu.com/3814-3/ https://www.openwall.com/lists/oss-security/2018/10/22/1 https://www.suse.com/security/cve/CVE-2018-18585/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

LOW

Base Severity

4.3

Share on: