PT-2018-10524 · R Core Team+1 · Haven R Package+1
CVE-2018-11365
·
Publicado
2018-05-22
·
Atualizado
2023-10-05
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ReadStat version 0.1.1
haven R package (affected versions not specified)
Description
The issue involves an infinite loop condition, a memory leak associated with an
iconv open call, and a heap-based buffer over-read via an unterminated string. This could lead to Denial of Service or other undefined behaviors.Recommendations
For ReadStat version 0.1.1, update to a version that fixes the infinite loop in
sas/readstat sas7bcat read.c.
For the haven R package, consider restricting the use of the underlying ReadStat library until a patch is available.
As a temporary workaround, consider disabling the iconv open call to minimize the risk of memory leaks.
Avoid using unterminated strings in the affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability in the haven R package.Exploit
Correção
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Readstat
Haven R Package