Multiple vulnerabilities have been found in cabextract and libmspack, the worst of which could result in a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201903-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: cabextract, libmspack: Multiple vulnerabilities Date: March 28, 2019 Bugs: #662874, #669280 ID: 201903-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in cabextract and libmspack, the worst of which could result in a Denial of Service. Background ========= cabextract is free software for extracting Microsoft cabinet files. libmspack is a portable library for some loosely related Microsoft compression formats Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/cabextract < 1.8 > = 1.8 2 dev-libs/libmspack < 0.8_alpha > = 0.8_alpha ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in cabextract and libmspack. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE's for details. Workaround ========= There is no known workaround at this time. Resolution ========= All cabextract users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/cabextract-1.8" All libmspack users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libmspack-0.8_alpha" References ========= [ 1 ] CVE-2018-14679 https://nvd.nist.gov/vuln/detail/CVE-2018-14679 [ 2 ] CVE-2018-14680 https://nvd.nist.gov/vuln/detail/CVE-2018-14680 [ 3 ] CVE-2018-14681 https://nvd.nist.gov/vuln/detail/CVE-2018-14681 [ 4 ] CVE-2018-14682 https://nvd.nist.gov/vuln/detail/CVE-2018-14682 [ 5 ] CVE-2018-18584 https://nvd.nist.gov/vuln/detail/CVE-2018-18584 [ 6 ] CVE-2018-18585 https://nvd.nist.gov/vuln/detail/CVE-2018-18585 [ 7 ] CVE-2018-18586 https://nvd.nist.gov/vuln/detail/CVE-2018-18586 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201903-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Latest stable releases of libmspack and cabextract, includes security fixes for CVE-2018-14680, CVE-2018-14681, CVE-2018-14682, CVE-2018-18584, CVE-2018-18585. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c73d257297 2018-11-17 02:07:42.735718 --------------------------------------------------------------------------------Name : cabextract Product : Fedora 27 Version : 1.9 Release : 1.fc27 URL : https://www.cabextract.org.uk/ Summary : Utility for extracting cabinet (.cab) archives Description : cabextract is a program which can extract files from cabinet (.cab) archives. --------------------------------------------------------------------------------Update Information: Latest stable releases of libmspack and cabextract, includes security fixes for CVE-2018-14680, CVE-2018-14681, CVE-2018-14682, CVE-2018-18584, CVE-2018-18585 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 6 2018 Rex Dieter - 1.9-1 - 1.9 * Tue Oct 30 2018 Rex Dieter - 1.8-1 - 1.8 * Wed Jul 25 2018 Rex Dieter - 1.7-1 - 1.7 (#1186186) * Thu Jul 12 2018 Fedora Release Engineering - 1.5-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Wed Feb 7 2018 Fedora Release Engineering - 1.5-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1610941 - CVE-2018-14682 libmspack: off-by-one error in the TOLOWER() macro for CHM decompression https://bugzilla.redhat.com/show_bug.cgi?id=1610941 [ 2 ] Bug #1610896 - CVE-2018-14681 libmspack: out-of-bounds write in kwajd_read_headers in mspack/kwajd.c https://bugzilla.redhat.com/show_bug.cgi?id=1610896 [ 3 ] Bug #1610934 - CVE-2018-14680 libmspack: off-by-one error in the CHM chunk number validity checks https://bugzilla.redhat.com/show_bug.cgi?id=1610934 [ 4 ] Bug #1644215 - CVE-2018-18585 libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes https://bugzilla.redhat.com/show_bug.cgi?id=1644215 [ 5 ] Bug #1644214 - CVE-2018-18584 libmspack: Out-of-bounds write in mspack/cab.h https://bugzilla.redhat.com/show_bug.cgi?id=1644214 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-c73d257297' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Latest stable releases of libmspack and cabextract, includes security fixes for CVE-2018-14680, CVE-2018-14681, CVE-2018-14682, CVE-2018-18584, CVE-2018-18585. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-cb337fb199 2018-11-13 02:25:35.636330 --------------------------------------------------------------------------------Name : cabextract Product : Fedora 28 Version : 1.9 Release : 1.fc28 URL : https://www.cabextract.org.uk/ Summary : Utility for extracting cabinet (.cab) archives Description : cabextract is a program which can extract files from cabinet (.cab) archives. --------------------------------------------------------------------------------Update Information: Latest stable releases of libmspack and cabextract, includes security fixes for CVE-2018-14680, CVE-2018-14681, CVE-2018-14682, CVE-2018-18584, CVE-2018-18585 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 6 2018 Rex Dieter - 1.9-1 - 1.9 * Tue Oct 30 2018 Rex Dieter - 1.8-1 - 1.8 * Wed Jul 25 2018 Rex Dieter - 1.7-1 - 1.7 (#1186186) * Thu Jul 12 2018 Fedora Release Engineering - 1.5-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1644215 - CVE-2018-18585 libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes https://bugzilla.redhat.com/show_bug.cgi?id=1644215 [ 2 ] Bug #1644214 - CVE-2018-18584 libmspack: Out-of-bounds write in mspack/cab.h https://bugzilla.redhat.com/show_bug.cgi?id=1644214 [ 3 ] Bug #1610941 - CVE-2018-14682 libmspack: off-by-one error in the TOLOWER() macro for CHM decompression https://bugzilla.redhat.com/show_bug.cgi?id=1610941 [ 4 ] Bug #1610934 - CVE-2018-14680 libmspack: off-by-one error in the CHM chunk number validity checks https://bugzilla.redhat.com/show_bug.cgi?id=1610934 [ 5 ] Bug #1610896 - CVE-2018-14681 libmspack: out-of-bounds write in kwajd_read_headers in mspack/kwajd.c https://bugzilla.redhat.com/show_bug.cgi?id=1610896 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-cb337fb199' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Latest stable releases of libmspack and cabextract, includes security fixes for CVE-2018-14680, CVE-2018-14681, CVE-2018-14682, CVE-2018-18584, CVE-2018-18585. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a5953af115 2018-11-13 02:18:59.072814 --------------------------------------------------------------------------------Name : cabextract Product : Fedora 29 Version : 1.9 Release : 1.fc29 URL : https://www.cabextract.org.uk/ Summary : Utility for extracting cabinet (.cab) archives Description : cabextract is a program which can extract files from cabinet (.cab) archives. --------------------------------------------------------------------------------Update Information: Latest stable releases of libmspack and cabextract, includes security fixes for CVE-2018-14680, CVE-2018-14681, CVE-2018-14682, CVE-2018-18584, CVE-2018-18585 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 6 2018 Rex Dieter - 1.9-1 - 1.9 * Tue Oct 30 2018 Rex Dieter - 1.8-1 - 1.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #1644215 - CVE-2018-18585 libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes https://bugzilla.redhat.com/show_bug.cgi?id=1644215 [ 2 ] Bug #1644214 - CVE-2018-18584 libmspack: Out-of-bounds write in mspack/cab.h https://bugzilla.redhat.com/show_bug.cgi?id=1644214 [ 3 ] Bug #1610896 - CVE-2018-14681 libmspack: out-of-bounds write in kwajd_read_headers in mspack/kwajd.c https://bugzilla.redhat.com/show_bug.cgi?id=1610896 [ 4 ] Bug #1610934 - CVE-2018-14680 libmspack: off-by-one error in the CHM chunk number validity checks https://bugzilla.redhat.com/show_bug.cgi?id=1610934 [ 5 ] Bug #1610941 - CVE-2018-14682 libmspack: off-by-one error in the TOLOWER() macro for CHM decompression https://bugzilla.redhat.com/show_bug.cgi?id=1610941 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a5953af115' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been found in cabextract, allowing remote attackers to execute arbitrary code or cause a Denial of Service condition. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201312-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: cabextract: Multiple vulnerabilities Date: December 14, 2013 Bugs: #329891 ID: 201312-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in cabextract, allowing remote attackers to execute arbitrary code or cause a Denial of Service condition. Background ========= cabextract is free software for extracting Microsoft cabinet files. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/cabextract < 1.3 > = 1.3 Description ========== Multiple vulnerabilities have been discovered in cabextract. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could entice a user to open a specially-crafted archive in a .cab file, related to the libmspack library, potentially resulting in arbitrary code execution or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All cabextract users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/cabextract-1.3" NOTE: This is a legacy GLSA. Updates for all affected architectures are available since August 03, 2010. It is likely that your systemis already no longer affected by this issue. References ========= [ 1 ] CVE-2010-2800 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2800 [ 2 ] CVE-2010-2801 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2801 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201312-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
The upstream developers discovered a problem in cabextract, a tool to extract cabinet files. The program was able to overwrite files in upper directories. This could lead an attacker to overwrite arbitrary files.. -------------------------------------------------------------------------- Debian Security Advisory DSA 574-1
Get the latest Linux and open source security news straight to your inbox.