4.3
CVSSv2

CVE-2015-4470

Published: 11/06/2015 Updated: 09/06/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the inflate function in mszipd.c in libmspack prior to 0.5 allows remote malicious users to cause a denial of service (buffer over-read and application crash) via a crafted CAB archive.

Vulnerable Product Search on Vulmon Subscribe to Product

libmspack project libmspack

Vendor Advisories

Debian Bug report logs - #775498 libmspack: CVE-2015-4470: off-by-one buffer over-read in mspack/mszipdc Package: libmspack0; Maintainer for libmspack0 is Marc Dequènes (Duck) <Duck@DuckCorporg>; Source for libmspack0 is src:libmspack (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Fri, 16 J ...