PT-2018-10523 · R+1 · Haven R Package+1

Evan Miller

·

Published

2018-05-22

·

Updated

2023-10-05

·

CVE-2018-11364

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ReadStat version 0.1.1 haven R package (affected versions not specified)
Description The issue is related to multiple flaws in the ReadStat library, including an infinite loop condition, a memory leak associated with an iconv open call, and a heap-based buffer over-read via an unterminated string. These flaws could lead to Denial of Service or other undefined behaviors.
Recommendations For ReadStat version 0.1.1, update to a version that fixes the memory leak and other issues. For the haven R package, apply any available patches or updates that address the vulnerabilities in the underlying ReadStat library. As a temporary workaround, consider restricting the use of the sav parse machine integer info record function in spss/readstat sav read.c until a patch is available.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

CVE-2018-11364
RSEC-2023-5

Affected Products

Readstat
Haven R Package