Bug 1548018 (CVE-2018-1000097)

Summary: CVE-2018-1000097 sharutils: heap-buffer-overflow in find_archive in unshar.c
Product: [Other] Security Response Reporter: Laura Pardo <lpardo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: kasal, ppisar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A heap-based out-of-bounds read flaw was found in the way Sharutils parsed archive files. An attacker could potentially use this flaw to crash Unshar by tricking it into processing crafted archive files.
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 03:40:52 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1548019, 1554739, 1554740    
Bug Blocks: 1548021    
Attachments:
Description Flags
A proposed fix none

Description Laura Pardo 2018-02-22 14:29:57 UTC
A flaw was found in Sharutils 4.15.2, a heap buffer overflow in Unshar. This may allow an attacker to perform a Denial of Service attack or possible have another unspecified impact.

Comment 1 Laura Pardo 2018-02-22 14:30:23 UTC
Created sharutils tracking bugs for this issue:

Affects: fedora-all [bug 1548019]

Comment 2 Petr Pisar 2018-02-22 15:10:07 UTC
Is this the upstream bug report <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00004.html>? (The same author send another bug report sooner <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00003.html>.)

Comment 3 Petr Pisar 2018-02-22 16:04:42 UTC
Created attachment 1399466 [details]
A proposed fix

Comment 4 Petr Pisar 2018-02-22 16:06:51 UTC
(In reply to Petr Pisar from comment #2)
> Is this this upstream bug report
> <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00004.html>?

It is according to the back trace.

Comment 5 Fedora Update System 2018-03-06 17:23:18 UTC
sharutils-4.15.2-8.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2018-03-06 17:29:28 UTC
sharutils-4.15.2-6.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.