Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-6419

Опубликовано: 07 авг. 2017
Источник: debian

Описание

mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libmspackfixed0.6-1package
clamavfixed0.99.3~beta1+dfsg-1package
clamavfixed0.99.4+dfsg-1+deb9u1stretchpackage

Примечания

  • https://bugzilla.clamav.net/show_bug.cgi?id=11701

  • https://github.com/vrtadmin/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1

  • ClamAV uses the libmspack system library when available. This is the

  • case from starting from Debian Jessie. Debian Wheezy does not have

  • have libmspack and thus need to have the fix as well in the

  • src:clamav source package.

  • libmspack: https://github.com/kyz/libmspack/commit/6139a0b9e93fcb7fcf423e56aa825bc869e02229

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

CVSS3: 6.5
redhat
почти 9 лет назад

mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

CVSS3: 7.8
nvd
больше 8 лет назад

mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

CVSS3: 7.8
github
больше 3 лет назад

mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

suse-cvrf
почти 8 лет назад

Security update for clamav