Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1548018 - (CVE-2018-1000097) CVE-2018-1000097 sharutils: heap-buffer-overflow in find_archive in unshar.c
CVE-2018-1000097 sharutils: heap-buffer-overflow in find_archive in unshar.c
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20180221,reported=2...
: Security
Depends On: 1548019 1554739 1554740
Blocks: 1548021
  Show dependency treegraph
 
Reported: 2018-02-22 09:29 EST by Laura Pardo
Modified: 2018-03-29 18:05 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A heap-based out-of-bounds read flaw was found in the way Sharutils parsed archive files. An attacker could potentially use this flaw to crash Unshar by tricking it into processing crafted archive files.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
A proposed fix (2.34 KB, patch)
2018-02-22 11:04 EST, Petr Pisar
no flags Details | Diff

  None (edit)
Description Laura Pardo 2018-02-22 09:29:57 EST
A flaw was found in Sharutils 4.15.2, a heap buffer overflow in Unshar. This may allow an attacker to perform a Denial of Service attack or possible have another unspecified impact.
Comment 1 Laura Pardo 2018-02-22 09:30:23 EST
Created sharutils tracking bugs for this issue:

Affects: fedora-all [bug 1548019]
Comment 2 Petr Pisar 2018-02-22 10:10:07 EST
Is this the upstream bug report <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00004.html>? (The same author send another bug report sooner <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00003.html>.)
Comment 3 Petr Pisar 2018-02-22 11:04 EST
Created attachment 1399466 [details]
A proposed fix
Comment 4 Petr Pisar 2018-02-22 11:06:51 EST
(In reply to Petr Pisar from comment #2)
> Is this this upstream bug report
> <http://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00004.html>?

It is according to the back trace.
Comment 5 Fedora Update System 2018-03-06 12:23:18 EST
sharutils-4.15.2-8.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.
Comment 6 Fedora Update System 2018-03-06 12:29:28 EST
sharutils-4.15.2-6.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.