Lucene search

K
nvd[email protected]NVD:CVE-2018-18584
HistoryOct 23, 2018 - 2:29 a.m.

CVE-2018-18584

2018-10-2302:29:00
CWE-787
web.nvd.nist.gov

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

High

0.345 Low

EPSS

Percentile

97.1%

In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.

Affected configurations

NVD
Node
cabextract_projectcabextractRange<1.8
OR
libmspack_projectlibmspackMatch0.3alpha
OR
libmspack_projectlibmspackMatch0.4alpha
OR
libmspack_projectlibmspackMatch0.5alpha
OR
libmspack_projectlibmspackMatch0.6alpha
OR
libmspack_projectlibmspackMatch0.7alpha
OR
libmspack_projectlibmspackMatch0.7.1alpha
Node
debiandebian_linuxMatch8.0
Node
redhatenterprise_linuxMatch7.0
Node
canonicalubuntu_linuxMatch12.04esm
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch16.04lts
OR
canonicalubuntu_linuxMatch18.04lts
OR
canonicalubuntu_linuxMatch18.10
Node
suselinux_enterprise_serverMatch11sp3ltss
OR
suselinux_enterprise_serverMatch12galtss
OR
suselinux_enterprise_serverMatch12sp1ltss
OR
suselinux_enterprise_serverMatch12sp2ltss
Node
starwindsoftwarestarwind_virtual_sanMatch-vsphere

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

High

0.345 Low

EPSS

Percentile

97.1%