CVE-2018-18585 Information
Description
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has ‘\0’ as its first or second character (such as the /\0\ name).
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Reference
https://access.redhat.com/errata/RHSA-2019:2049 https://access.redhat.com/security/cve/cve-2018-18585 https://bugs.debian.org/911637 https://github.com/kyz/libmspack/commit/8759da8db6ec9e866cb8eb143313f397f925bb4f https://lists.debian.org/debian-lts-announce/2018/10/msg00017.html https://security.gentoo.org/glsa/201903-20 https://tools.cisco.com/security/center/viewAlert.x?alertId=59134 https://usn.ubuntu.com/3814-1/ https://usn.ubuntu.com/3814-2/ https://usn.ubuntu.com/3814-3/ https://www.openwall.com/lists/oss-security/2018/10/22/1 https://www.suse.com/security/cve/CVE-2018-18585/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
4.3
Share on: