6.8
CVSSv2

CVE-2015-4472

Published: 11/06/2015 Updated: 22/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack prior to 0.5 allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file.

Vulnerable Product Search on Vulmon Subscribe to Product

libmspack project libmspack

Vendor Advisories

Debian Bug report logs - #775687 libmspack: CVE-2015-4472: CHM decompression: another pointer arithmetic overflow Package: libmspack0; Maintainer for libmspack0 is Marc Dequènes (Duck) <Duck@DuckCorporg>; Source for libmspack0 is src:libmspack (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: S ...