CVE-2018-11723

NameCVE-2018-11723
DescriptionThe libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file. NOTE: the vendor has disputed this as described in libyal/libpff issue 66 on GitHub
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs901967

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libpff (PTS)jessie20120802-2vulnerable
stretch20120802-5vulnerable
buster20180714-1fixed
bullseye, bookworm20180714-3fixed
sid, trixie20180714-3.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libpffsource(unstable)20180714-1low901967

Notes

[stretch] - libpff <no-dsa> (Minor issue)
[jessie] - libpff <no-dsa> (Minor issue)
http://seclists.org/fulldisclosure/2018/Jun/15
https://github.com/libyal/libpff/issues/64
https://github.com/libyal/libpff/commit/7b92bcace7e743cc9417e3cc3e4eee29abb70cf5

Search for package or bug name: Reporting problems