Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-48172

Опубликовано: 04 июл. 2025
Источник: debian

Описание

CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chmlibnot-affectedpackage

Примечания

  • Introduced with: https://github.com/sumatrapdfreader/sumatrapdf/commit/39528ca130c6ceac99c3d96ce7a26d9e99a0d3a9

  • Fixed by: https://github.com/sumatrapdfreader/sumatrapdf/commit/08179946a745cf1605e4b9670942ec1a6e1f4c5d

Связанные уязвимости

CVSS3: 5.6
ubuntu
7 месяцев назад

CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.

CVSS3: 5.6
nvd
7 месяцев назад

CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.

CVSS3: 5.6
github
7 месяцев назад

CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.