Описание
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | uses system libmspack |
| bionic | not-affected | uses system libmspack |
| cosmic | not-affected | uses system libmspack |
| devel | not-affected | uses system libmspack |
| disco | not-affected | uses system libmspack |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra/bionic | not-affected | uses system libmspack |
| esm-infra/focal | not-affected | uses system libmspack |
| esm-infra/xenial | not-affected | uses system libmspack |
| focal | not-affected | uses system libmspack |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 0.6-3 |
| bionic | not-affected | 0.6-3 |
| cosmic | not-affected | 0.6-3 |
| devel | not-affected | 0.6-3 |
| disco | not-affected | 0.6-3 |
| esm-infra-legacy/trusty | released | 0.4-1ubuntu0.1~esm2 |
| esm-infra/bionic | not-affected | 0.6-3 |
| esm-infra/focal | not-affected | 0.6-3 |
| esm-infra/xenial | released | 0.5-1ubuntu0.16.04.1 |
| focal | not-affected | 0.6-3 |
Показывать по
EPSS
4.3 Medium
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, ...
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.
EPSS
4.3 Medium
CVSS2
5.5 Medium
CVSS3