CVE-2018-11723

NameCVE-2018-11723
Description** DISPUTED ** The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file. NOTE: the vendor has disputed this as described in libyal/libpff issue 66 on GitHub.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow (attack range: local)
Debian Bugs901967

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libpff (PTS)jessie20120802-2vulnerable
stretch20120802-5vulnerable
buster, sid20120802-5.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libpffsource(unstable)(unfixed)low901967

Notes

[stretch] - libpff <no-dsa> (Minor issue)
[jessie] - libpff <no-dsa> (Minor issue)
http://seclists.org/fulldisclosure/2018/Jun/15
https://github.com/libyal/libpff/issues/64
https://github.com/libyal/libpff/commit/7b92bcace7e743cc9417e3cc3e4eee29abb70cf5

Search for package or bug name: Reporting problems