CVE-2018-5345
published 2018-01-12CVE-2018-5345: A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code…
PriorityP434high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.19%
80.5th percentile
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | gcab | < gcab 0.7-7 (bookworm) | gcab 0.7-7 (bookworm) |
| gnome | gcab | <= 0.7.4 | — |
| gnome | gcab | >= 0 < 0.7-7 | 0.7-7 |
| gnome | gcab | >= 0 < 0.7-7 | 0.7-7 |
| gnome | gcab | >= 0 < 0.7-7 | 0.7-7 |
| gnome | gcab | >= 0 < 0.7-7 | 0.7-7 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-28gw-xjhw-6cm5: A stack-based buffer overflow within GNOME gcab through 0
ghsa_unreviewed·2022-05-13
CVE-2018-5345 [HIGH] CWE-787 GHSA-28gw-xjhw-6cm5: A stack-based buffer overflow within GNOME gcab through 0
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
OSV
CVE-2018-5345: A stack-based buffer overflow within GNOME gcab through 0
osv·2018-01-12·CVSS 7.8
CVE-2018-5345 [HIGH] CVE-2018-5345: A stack-based buffer overflow within GNOME gcab through 0
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
Ubuntu
gcab vulnerability
vendor_ubuntu·2018-01-24
CVE-2018-5345 gcab vulnerability
Title: gcab vulnerability
Summary: gcab could be made to crash or run programs if it opened a specially
crafted file.
Richard Hughes discovered that gcab incorrectly handled certain malformed
cabinet files. If a user or automated system were tricked into opening a
specially crafted cabinet file, a remote attacker could use this issue to
cause gcab to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Debian
CVE-2018-5345: gcab - A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited b...
vendor_debian·2018·CVSS 7.8
CVE-2018-5345 [HIGH] CVE-2018-5345: gcab - A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited b...
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
Scope: local
bookworm: resolved (fixed in 0.7-7)
bullseye: resolved (fixed in 0.7-7)
forky: resolved (fixed in 0.7-7)
sid: resolved (fixed in 0.7-7)
trixie: resolved (fixed in 0.7-7)
Red Hat
gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution
vendor_redhat·2017-12-19·CVSS 7.8
CVE-2018-5345 [HIGH] CWE-121 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution
gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
Package: gcab (Red Hat Enterprise Linux 8) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5345 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code exectuion [fedora-all]
bugzilla·2017-12-21·CVSS 7.8
CVE-2018-5345 [HIGH] CVE-2018-5345 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code exectuion [fedora-all]
CVE-2018-5345 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code exectuion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2018-5345 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution
bugzilla·2017-12-19·CVSS 7.8
CVE-2018-5345 [HIGH] CVE-2018-5345 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution
CVE-2018-5345 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution
Versions of gcab <= 7.4 are vulnerable to a stack-based buffer overflow when extracting maliciously constructed .cab files. An attacker could potentially exploit this to execute arbitrary code.
Original bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1527062
Discussion:
Upstream would like to make a new release before the holidays, but obviously would like to include the fix with the new tarball. Can we get some guidance on what we should do? Thanks.
---
Created gcab tracking bugs for this issue:
Affects: fedora-all [bug 1528141]
---
Hi Sam Fowler, hi Richard,
Would it be possible to open up the original bug report? This has restricted access and there is no
https://access.redhat.com/errata/RHSA-2018:0350https://bugzilla.redhat.com/show_bug.cgi?id=1527296https://usn.ubuntu.com/3546-1/https://www.debian.org/security/2018/dsa-4095https://access.redhat.com/errata/RHSA-2018:0350https://bugzilla.redhat.com/show_bug.cgi?id=1527296https://usn.ubuntu.com/3546-1/https://www.debian.org/security/2018/dsa-4095
2018-01-12
Published