Lack of data validation In libmspack
Description
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
alpine v3.11 | 0.7.1_alpha-r0 | ||
alpine v3.8 | 0.7.1_alpha-r0 | ||
debian 12 | 0.7-1 | ||
debian 13 | 0.7-1 | ||
debian 14 | 0.7-1 | ||
alpine v3.10 | 0.7.1_alpha-r0 | ||
alpine v3.5 | 0.7.1_alpha-r0 | ||
alpine v3.6 | 0.7.1_alpha-r0 | ||
alpine v3.7 | 0.7.1_alpha-r0 | ||
debian 11 | 0.7-1 |
1-10 of 12
10
Aliases
1. 2. 3. 4. 5. 6. 7.