Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-18585

Опубликовано: 17 окт. 2018
Источник: redhat
CVSS3: 3.3

Описание

chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).

Отчет

This issue affects the versions of libmspack as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8libmspackNot affected
Red Hat Enterprise Linux 7libmspackFixedRHSA-2019:204906.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1644215libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 7 лет назад

chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).

CVSS3: 4.3
nvd
больше 7 лет назад

chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).

CVSS3: 4.3
debian
больше 7 лет назад

chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accept ...

CVSS3: 4.3
github
больше 3 лет назад

chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).

suse-cvrf
почти 7 лет назад

Security update for libmspack

3.3 Low

CVSS3