An issue was discovered in kwajdreadheaders in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
{ "vanir_signatures": [ { "id": "CVE-2018-14681-ebb257ff", "digest": { "threshold": 0.9, "line_hashes": [ "264125639601368245136278382040962299940", "334718959738228674956836817475169085946", "129263725176395171497904630117284598573", "136055985965663008756139860224137290491", "146921429704295347375559488414009961315", "144048888467957435751834250567563075182", "111846584464331271926986855392744924426", "203836619199442944830654375939473252323", "81676947660109281998418610702684930460", "298075990359636591353990776340018337053", "291184430367398170553833683326145169146", "265994721061227409424378697157226067255", "282128057683887539700009755939422265141", "145568330504166830716940528839867775308", "47732878296738844481897533567175310364", "296738990979170437360220607543689989228", "310121185771599670866381063311104525529", "274428706265141814401783177908660083895", "71631741594013791888316882536923655880", "126237243167368149135907565162241690162", "134367768589457487684380498779829148207" ] }, "signature_type": "Line", "target": { "file": "libmspack/mspack/kwajd.c" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/kyz/libmspack/commit/0b0ef9344255ff5acfac6b7af09198ac9c9756c8" }, { "id": "CVE-2018-14681-f0630062", "digest": { "length": 2697.0, "function_hash": "9188850034302970685971634658391947089" }, "signature_type": "Function", "target": { "file": "libmspack/mspack/kwajd.c", "function": "kwajd_read_headers" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/kyz/libmspack/commit/0b0ef9344255ff5acfac6b7af09198ac9c9756c8" } ] }