Bugzilla – Bug 1113039
VUL-1: CVE-2018-18585: libmspack: chmd_read_headers() reject files with blank filenames,
Last modified: 2020-10-27 15:28:00 UTC
CVE-2018-18585 FTR, three CVEs were assigned by MITRE, whereeas one is explicitly marked as DISPUTED, because upstream makes clear in the changelog entry, that the chmextract utility is more an example code how to use the library rather than "productised" binaries. Still a CVE was assigned for downstreams using it as such. Upstream changelog: 2018-10-17 Stuart Caie <kyzer@cabextract.org.uk> * chmd_read_headers(): again reject files with blank filenames, this time because their 1st or 2nd byte is null, not because their length is zero. Thanks again to Hanno Böck for finding the issue. Upstream fix: https://github.com/kyz/libmspack/commit/8759da8db6ec9e866cb8eb143313f397f925bb4f References: https://www.openwall.com/lists/oss-security/2018/10/23/11 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-18585
This is an autogenerated message for OBS integration: This bug (1113039) was mentioned in https://build.opensuse.org/request/show/644862 15.0 / libmspack https://build.opensuse.org/request/show/644863 42.3 / libmspack
This is an autogenerated message for OBS integration: This bug (1113039) was mentioned in https://build.opensuse.org/request/show/645188 15.0 / libmspack https://build.opensuse.org/request/show/645191 42.3 / libmspack
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2018-11-12. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/64167
openSUSE-SU-2018:3562-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1113038,1113039,1113040 CVE References: CVE-2018-18584,CVE-2018-18585,CVE-2018-18586 Sources used: openSUSE Leap 42.3 (src): libmspack-0.5-8.3.1
SUSE-SU-2019:0748-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1113038,1113039 CVE References: CVE-2018-18584,CVE-2018-18585 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): libmspack-0.6-3.3.11 SUSE Linux Enterprise Module for Basesystem 15 (src): libmspack-0.6-3.3.11 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:13992-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1113038,1113039 CVE References: CVE-2018-18584,CVE-2018-18585 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): libmspack-0.0.20060920alpha-74.11.6.1 SUSE Linux Enterprise Server 11-SP4 (src): libmspack-0.0.20060920alpha-74.11.6.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): libmspack-0.0.20060920alpha-74.11.6.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2020:2711-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1113038,1113039,1130489,1141680 CVE References: CVE-2018-18584,CVE-2018-18585,CVE-2019-1010305 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): libmspack-0.4-15.7.1 SUSE Linux Enterprise Server 12-SP5 (src): libmspack-0.4-15.7.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
DONE