8.8
CVSSv3

CVE-2018-14681

Published: 28/07/2018 Updated: 26/04/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in kwajd_read_headers in mspack/kwajd.c in libmspack prior to 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cabextract libmspack 0.6

cabextract libmspack 0.4

cabextract libmspack 0.0.20060920

cabextract project cabextract

cabextract libmspack 0.5

cabextract libmspack 0.3

debian debian linux 9.0

canonical ubuntu linux 16.04

debian debian linux 8.0

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

redhat enterprise linux workstation 7.0

redhat ansible tower 3.3

redhat enterprise linux desktop 7.0

redhat enterprise linux server 7.0

Vendor Advisories

Synopsis Low: libmspack security update Type/Severity Security Advisory: Low Topic An update for libmspack is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Critical: Red Hat Ansible Tower 331-2 Release - Container Image Type/Severity Security Advisory: Critical Topic Security Advisory Description Red Hat Ansible Tower 331 is now available and contains the following bug fixes: Fixed event callback error when in-line vaulted variabl ...
Several vulnerabilities were discovered in libsmpack, a library used to handle Microsoft compression formats A remote attacker could craft malicious CAB, CHM or KWAJ files and use these flaws to cause a denial of service via application crash, or potentially execute arbitrary code For the stable distribution (stretch), these problems have been fi ...
Debian Bug report logs - #904801 libmspack: CVE-2018-14680: libmspack now rejects blank CHM filenames Package: src:libmspack; Maintainer for src:libmspack is Marc Dequènes (Duck) <Duck@DuckCorporg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 28 Jul 2018 07:33:08 UTC Severity: important Tags: p ...
Debian Bug report logs - #904802 libmspack: CVE-2018-14679: off-by-one error in CHM PMGI/PMGL chunk number validity checks Package: src:libmspack; Maintainer for src:libmspack is Marc Dequènes (Duck) <Duck@DuckCorporg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 28 Jul 2018 07:33:11 UTC Severi ...
Debian Bug report logs - #904800 libmspack: CVE-2018-14682: Fix off-by-one error in chmd TOLOWER() fallback Package: src:libmspack; Maintainer for src:libmspack is Marc Dequènes (Duck) <Duck@DuckCorporg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 28 Jul 2018 07:33:05 UTC Severity: important T ...
Debian Bug report logs - #904799 libmspack: CVE-2018-14681: kwaj_read_headers(): fix handling of non-terminated strings Package: src:libmspack; Maintainer for src:libmspack is Marc Dequènes (Duck) <Duck@DuckCorporg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 28 Jul 2018 07:33:02 UTC Severity: ...
Several security issues were fixed in ClamAV ...
Several security issues were fixed in libmspack ...
ClamAV could be made to crash if it opened a specially crafted file ...
Several security issues were fixed in ClamAV ...
An issue was discovered in mspack/chmdc in libmspack before 07alpha There is an off-by-one error in the TOLOWER() macro for CHM decompression(CVE-2018-14682) An issue was discovered in mspack/chmdc in libmspack before 07alpha It does not reject blank CHM filenames(CVE-2018-14680) An issue was discovered in mspack/chmdc in libmspack before ...
An issue was discovered in kwajd_read_headers in mspack/kwajdc in libmspack before 07alpha Bad KWAJ file header extensions could cause a one or two byte overwrite(CVE-2018-14681) An issue was discovered in mspack/chmdc in libmspack before 07alpha There is an off-by-one error in the TOLOWER() macro for CHM decompression(CVE-2018-14682) An is ...