CVE-2015-4468
Published: 11 June 2015
Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
Priority
Status
Package | Release | Status |
---|---|---|
libmspack Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
|
bionic |
Not vulnerable
|
|
cosmic |
Not vulnerable
|
|
disco |
Not vulnerable
|
|
focal |
Not vulnerable
|
|
jammy |
Not vulnerable
|
|
kinetic |
Not vulnerable
|
|
lunar |
Not vulnerable
|
|
precise |
Does not exist
|
|
trusty |
Needed
|
|
upstream |
Released
(0.4-3)
|
|
utopic |
Ignored
(reached end-of-life)
|
|
vivid |
Not vulnerable
(0.5-1)
|
|
wily |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
yakkety |
Not vulnerable
|
|
zesty |
Not vulnerable
|
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4468
- http://www.openwall.com/lists/oss-security/2015/02/03/11
- https://bugs.debian.org/774726
- http://openwall.com/lists/oss-security/2015/02/03/11
- http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-pointer-arithmetic-overflow.patch?id=a25bb144795e526748b57884daf365732c7e2295
- NVD
- Launchpad
- Debian