Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14679

Опубликовано: 12 мая 2018
Источник: redhat
CVSS3: 4

Описание

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).

Отчет

This issue affects the versions of libmspack as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8libmspackNot affected
Red Hat Enterprise Linux 7libmspackFixedRHSA-2018:332730.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=1610890libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).

CVSS3: 6.5
nvd
больше 7 лет назад

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).

CVSS3: 6.5
debian
больше 7 лет назад

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. ...

suse-cvrf
почти 4 года назад

Security update for clamav

suse-cvrf
почти 4 года назад

Security update for clamav

4 Medium

CVSS3