PT-2018-10523 · R+1 · Haven R Package+1
Evan Miller
·
Published
2018-05-22
·
Updated
2023-10-05
·
CVE-2018-11364
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ReadStat version 0.1.1
haven R package (affected versions not specified)
Description
The issue is related to multiple flaws in the ReadStat library, including an infinite loop condition, a memory leak associated with an
iconv open call, and a heap-based buffer over-read via an unterminated string. These flaws could lead to Denial of Service or other undefined behaviors.Recommendations
For ReadStat version 0.1.1, update to a version that fixes the memory leak and other issues.
For the haven R package, apply any available patches or updates that address the vulnerabilities in the underlying ReadStat library.
As a temporary workaround, consider restricting the use of the
sav parse machine integer info record function in spss/readstat sav read.c until a patch is available.Exploit
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Readstat
Haven R Package