cbcvebase.
CVE-2018-18584
published 2018-10-23

CVE-2018-18584: In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
cabextract_projectcabextract< 1.81.8
cabextract_projectcabextract>= 0 < 1.4-51.4-5
cabextract_projectcabextract>= 0 < 1.4-51.4-5
cabextract_projectcabextract>= 0 < 1.4-51.4-5
cabextract_projectcabextract>= 0 < 1.4-51.4-5
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
clamavclamav>= 0 < 0.100.2+dfsg-1ubuntu0.14.04.20.100.2+dfsg-1ubuntu0.14.04.2
debiancabextract< cabextract 1.4-5 (bookworm)cabextract 1.4-5 (bookworm)
debiandebian_linux
debianlibmspack< cabextract 1.4-5 (bookworm)cabextract 1.4-5 (bookworm)
libmspack_projectlibmspack
libmspack_projectlibmspack
libmspack_projectlibmspack
libmspack_projectlibmspack
libmspack_projectlibmspack
libmspack_projectlibmspack
libmspack_projectlibmspack>= 0 < 0.8-10.8-1
libmspack_projectlibmspack>= 0 < 0.8-10.8-1
libmspack_projectlibmspack>= 0 < 0.8-10.8-1
libmspack_projectlibmspack>= 0 < 0.8-10.8-1
libmspack_projectlibmspack>= 0 < 0.5-1ubuntu0.16.04.30.5-1ubuntu0.16.04.3

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM