[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2019-1152 --- libmspack

ID: oval:org.secpod.oval:def:1700140Date: (C)2019-03-28   (M)2023-12-20
Class: PATCHFamily: unix




An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER macro for CHM decompression.An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service .An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.

Platform:
Amazon Linux 2
Product:
libmspack
Reference:
ALAS2-2019-1152
CVE-2018-14679
CVE-2018-14682
CVE-2018-14680
CVE-2018-14681
CVE    4
CVE-2018-14681
CVE-2018-14680
CVE-2018-14679
CVE-2018-14682
...
CPE    2
cpe:/a:libmspack:libmspack
cpe:/o:amazon:linux:2

© SecPod Technologies