Vulnerability CVE-2015-4468


Published: 2015-06-11

Description:
Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Libmspack project -> Libmspack 

 References:
https://bugs.debian.org/774726
http://www.securityfocus.com/bid/72486
http://openwall.com/lists/oss-security/2015/02/03/11
http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-pointer-arithmetic-overflow.patch?id=a25bb144795e526748b57884daf365732c7e2295

Copyright 2024, cxsecurity.com

 

Back to Top