CVE-2018-18584
23.10.2018, 02:29
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.Enginsight
| Vendor | Product | Version |
|---|---|---|
| cabextract_project | cabextract | 𝑥 < 1.8 |
| libmspack_project | libmspack | 0.3:alpha |
| libmspack_project | libmspack | 0.4:alpha |
| libmspack_project | libmspack | 0.5:alpha |
| libmspack_project | libmspack | 0.6:alpha |
| libmspack_project | libmspack | 0.7:alpha |
| libmspack_project | libmspack | 0.7.1:alpha |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| starwindsoftware | starwind_virtual_san | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cabextract |
| ||||||||||||||||||||||
| clamav |
| ||||||||||||||||||||||
| libmspack |
|
Common Weakness Enumeration
References