Logo
vulnerabilityCVE-2018-1000097
Name
CVE-2018-1000097
Source
NVD ( link)Debian ( link)
Description
Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run unshar command on a specially crafted file..
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
sharutils
Patched

Vulnerability Ratings#


7.8
other
6.8
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
4.15.2
Patched
yocto
master
4.15.2
Patched

Resolved with patches#


sharutils (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix a heap-buffer-overflow in find_archive()
=?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
CVE-2018-1000097

sharutils (yocto:master)

#
Title
Author
Resolve
1
Fix a heap-buffer-overflow in find_archive()
=?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
CVE-2018-1000097

sharutils (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix a heap-buffer-overflow in find_archive()
=?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
CVE-2018-1000097