CVE-2018-5345Out-of-bounds Write in Gcab

Severity
7.8HIGHNVD
EPSS
0.9%
top 24.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 13

Description

A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Also affects: Debian Linux 9.0, Ubuntu Linux 16.04, 17.10, Enterprise Linux 7.4, 7.6, 7.5

🔴Vulnerability Details

3
GHSA
GHSA-28gw-xjhw-6cm5: A stack-based buffer overflow within GNOME gcab through 02022-05-13
OSV
CVE-2018-5345: A stack-based buffer overflow within GNOME gcab through 02018-01-12
CVEList
CVE-2018-5345: A stack-based buffer overflow within GNOME gcab through 02018-01-12

📋Vendor Advisories

3
Ubuntu
gcab vulnerability2018-01-24
Debian
CVE-2018-5345: gcab - A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited b...2018
Red Hat
gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution2017-12-19

💬Community

2
Bugzilla
CVE-2018-5345 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code exectuion [fedora-all]2017-12-21
Bugzilla
CVE-2018-5345 gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution2017-12-19
CVE-2018-5345 — Out-of-bounds Write in Gnome Gcab | cvebase