Hide Forgot
mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file. Upstream patch: https://github.com/vrtadmin/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1
Created clamav tracking bugs for this issue: Affects: epel-all [bug 1483912] Affects: fedora-all [bug 1483911]
Created libmspack tracking bugs for this issue: Affects: fedora-all [bug 1483999]
Created libmspack tracking bugs for this issue: Affects: epel-all [bug 1484000]
Same as bug 1472776#c7 libclamav/libmspack.c only exist in clamav 0.99.3 [1], in 0.99.2 we only have libclamav/mspack.c [2]. [1] https://github.com/vrtadmin/clamav-devel/tree/0.99.3/libclamav [2] https://github.com/vrtadmin/clamav-devel/blob/0.99.2/libclamav/mspack.c