4.3
CVSSv3

CVE-2018-18585

Published: 23/10/2018 Updated: 25/10/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

chmd_read_headers in mspack/chmd.c in libmspack prior to 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kyzer libmspack 0.7

kyzer libmspack 0.6

kyzer libmspack 0.5

kyzer libmspack 0.4

kyzer libmspack 0.3

debian debian linux 8.0

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

suse linux enterprise server 11

suse linux enterprise server 12

starwindsoftware starwind virtual san -

Vendor Advisories

Synopsis Moderate: libmspack security update Type/Severity Security Advisory: Moderate Topic An update for libmspack is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score ...
Debian Bug report logs - #911640 libmspack: CVE-2018-18584: CAB block input buffer is one byte too small for maximal Quantum block Package: src:libmspack; Maintainer for src:libmspack is Marc Dequènes (Duck) <Duck@DuckCorporg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 22 Oct 2018 22:12:09 UTC ...
Debian Bug report logs - #911639 libmspack: CVE-2018-18586: add anti "/" and leading slash protection to chmextract Package: src:libmspack; Maintainer for src:libmspack is Marc Dequènes (Duck) <Duck@DuckCorporg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 22 Oct 2018 22:12:06 UTC Severity: m ...
Debian Bug report logs - #911637 libmspack: CVE-2018-18585: Avoid returning CHM file entries that are "blank" because they have embedded null bytes Package: src:libmspack; Maintainer for src:libmspack is Marc Dequènes (Duck) <Duck@DuckCorporg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 22 Oct ...
Several security issues were fixed in ClamAV ...
Several security issues were fixed in libmspack ...
Several security issues were fixed in ClamAV ...
In mspack/cabh in libmspack before 08alpha and cabextract before 18, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write(CVE-2018-18584) chmd_read_headers in mspack/chmdc in libmspack before 08alpha accepts a filename that has '\\0' as its first or second character (such as the "/\ ...
chmd_read_headers in mspack/chmdc in libmspack before 08alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name) ...