ZeroHour

CVE-2018-18584

CVSS 3.1
6.5 medium
EPSS
3%p87
Published
()
Modified
Description

In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.

Vendors
cabextract projectlibmspack projectdebianredhatcanonicalsusestarwindsoftware
Products
cabextract, libmspack, debian linux, enterprise linux, ubuntu linux, linux enterprise server, starwind virtual san
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.