Bug 1548018 (CVE-2018-1000097) - CVE-2018-1000097 sharutils: heap-buffer-overflow in find_archive in unshar.c
Summary: CVE-2018-1000097 sharutils: heap-buffer-overflow in find_archive in unshar.c
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-1000097
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=low,public=20180221,reported=2...
Depends On: 1548019 1554739 1554740
Blocks: 1548021
TreeView+ depends on / blocked
 
Reported: 2018-02-22 14:29 UTC by Laura Pardo
Modified: 2019-06-11 11:13 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A heap-based out-of-bounds read flaw was found in the way Sharutils parsed archive files. An attacker could potentially use this flaw to crash Unshar by tricking it into processing crafted archive files.
Clone Of:
Environment:
Last Closed: 2019-06-08 03:40:52 UTC


Attachments (Terms of Use)
A proposed fix (2.34 KB, patch)
2018-02-22 16:04 UTC, Petr Pisar
no flags Details | Diff

Description Laura Pardo 2018-02-22 14:29:57 UTC
A flaw was found in Sharutils 4.15.2, a heap buffer overflow in Unshar. This may allow an attacker to perform a Denial of Service attack or possible have another unspecified impact.

Comment 1 Laura Pardo 2018-02-22 14:30:23 UTC
Created sharutils tracking bugs for this issue:

Affects: fedora-all [bug 1548019]

Comment 2 Petr Pisar 2018-02-22 15:10:07 UTC
Is this the upstream bug report <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00004.html>? (The same author send another bug report sooner <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00003.html>.)

Comment 3 Petr Pisar 2018-02-22 16:04:42 UTC
Created attachment 1399466 [details]
A proposed fix

Comment 4 Petr Pisar 2018-02-22 16:06:51 UTC
(In reply to Petr Pisar from comment #2)
> Is this this upstream bug report
> <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00004.html>?

It is according to the back trace.

Comment 5 Fedora Update System 2018-03-06 17:23:18 UTC
sharutils-4.15.2-8.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2018-03-06 17:29:28 UTC
sharutils-4.15.2-6.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.