PT-2018-10524 · R Core Team+1 · Haven R Package+1

CVE-2018-11365

·

Publicado

2018-05-22

·

Atualizado

2023-10-05

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ReadStat version 0.1.1 haven R package (affected versions not specified)
Description The issue involves an infinite loop condition, a memory leak associated with an iconv open call, and a heap-based buffer over-read via an unterminated string. This could lead to Denial of Service or other undefined behaviors.
Recommendations For ReadStat version 0.1.1, update to a version that fixes the infinite loop in sas/readstat sas7bcat read.c. For the haven R package, consider restricting the use of the underlying ReadStat library until a patch is available. As a temporary workaround, consider disabling the iconv open call to minimize the risk of memory leaks. Avoid using unterminated strings in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability in the haven R package.

Exploit

Correção

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11365
RSEC-2023-5

Produtos afetados

Readstat
Haven R Package