Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1472776 - (CVE-2017-11423) CVE-2017-11423 libmspack, clamav: Stack-based buffer over-read in cabd_read_string function
CVE-2017-11423 libmspack, clamav: Stack-based buffer over-read in cabd_read_s...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20170718,repor...
: Security
Depends On: 1472777 1472778 1483999 1484000
Blocks:
  Show dependency treegraph
 
Reported: 2017-07-19 07:45 EDT by Adam Mariš
Modified: 2018-09-26 01:45 EDT (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-09-26 01:45:22 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Adam Mariš 2017-07-19 07:45:58 EDT
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha,
as used in ClamAV 0.99.2 and other products, allows remote attackers to
cause a denial of service (stack-based buffer over-read and application
crash) via a crafted CAB file.

Reference:

https://github.com/hackerlib/hackerlib-vul/tree/master/clamav-vul

Upstream bug:

https://bugzilla.clamav.net/show_bug.cgi?id=11873
Comment 1 Adam Mariš 2017-07-19 07:46:28 EDT
Created clamav tracking bugs for this issue:

Affects: epel-all [bug 1472777]
Affects: fedora-all [bug 1472778]
Comment 2 Sergio Monteiro Basto 2017-07-19 07:50:12 EDT
Adam Mariš , can I sergio@serjux.com have permission to look  at 
https://bugzilla.clamav.net/show_bug.cgi?id=11873 ? 

Thanks
Comment 3 Adam Mariš 2017-08-22 07:18:05 EDT
(In reply to Sergio Monteiro Basto from comment #2)
> Adam Mariš , can I sergio@serjux.com have permission to look  at 
> https://bugzilla.clamav.net/show_bug.cgi?id=11873 ? 
> 
> Thanks

Sorry, I can't help you with that. Neither do I have access there.
Comment 4 Adam Mariš 2017-08-22 08:46:01 EDT
Created libmspack tracking bugs for this issue:

Affects: fedora-all [bug 1483999]
Comment 5 Adam Mariš 2017-08-22 08:48:03 EDT
Created libmspack tracking bugs for this issue:

Affects: epel-all [bug 1484000]
Comment 6 Tuomo Soini 2017-09-20 13:21:25 EDT
Adam, rhel7 tracking bug is still missing?
Comment 7 Sergio Monteiro Basto 2018-01-10 23:03:23 EST
clamav source , clean and not clean does not contain any cabd_read_string function neither libclamav/libmspack.c only libclamav/mspack.c [2], i.e those function only available on version 0.99.3 [3] 
anyway maybe also applicable to libmspack itself [1] 


[1]
https://apps.fedoraproject.org/packages/libmspack

[2]
https://github.com/vrtadmin/clamav-devel/blob/0.99.2/libclamav/mspack.c

[3]
https://github.com/vrtadmin/clamav-devel/tree/0.99.3/libclamav

Note You need to log in before you can comment on or make changes to this bug.