ALT-PU-2015-1694-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-9732
The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.
Modified: 2024-11-21
CVE-2015-4467
The chmd_init_decomp function in chmd.c in libmspack before 0.5 does not properly validate the reset interval, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted CHM file.
- http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-division-by-zero.patch?id=a25bb144795e526748b57884daf365732c7e2295
- http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-division-by-zero.patch?id=a25bb144795e526748b57884daf365732c7e2295
- [oss-security] 20150203 Possible CVE Requests: libmspack: several issues
- [oss-security] 20150203 Possible CVE Requests: libmspack: several issues
- 72488
- 72488
- https://bugs.debian.org/774725
- https://bugs.debian.org/774725
Modified: 2024-11-21
CVE-2015-4468
Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
- http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-pointer-arithmetic-overflow.patch?id=a25bb144795e526748b57884daf365732c7e2295
- http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-pointer-arithmetic-overflow.patch?id=a25bb144795e526748b57884daf365732c7e2295
- [oss-security] 20150203 Possible CVE Requests: libmspack: several issues
- [oss-security] 20150203 Possible CVE Requests: libmspack: several issues
- 72486
- 72486
- https://bugs.debian.org/774726
- https://bugs.debian.org/774726
Modified: 2024-11-21
CVE-2015-4469
The chmd_read_headers function in chmd.c in libmspack before 0.5 does not validate name lengths, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
- http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-name-field-boundaries.patch?id=a25bb144795e526748b57884daf365732c7e2295
- http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-name-field-boundaries.patch?id=a25bb144795e526748b57884daf365732c7e2295
- [oss-security] 20150203 Possible CVE Requests: libmspack: several issues
- [oss-security] 20150203 Possible CVE Requests: libmspack: several issues
- 72486
- 72486
- https://bugs.debian.org/774726
- https://bugs.debian.org/774726
Modified: 2024-11-21
CVE-2015-4470
Off-by-one error in the inflate function in mszipd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CAB archive.
Modified: 2024-11-21
CVE-2015-4471
Off-by-one error in the lzxd_decompress function in lzxd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer under-read and application crash) via a crafted CAB archive.
- [oss-security] 20150203 Possible CVE Requests: libmspack: several issues
- [oss-security] 20150203 Possible CVE Requests: libmspack: several issues
- 72492
- 72492
- https://bugs.debian.org/775499
- https://bugs.debian.org/775499
- https://github.com/kyz/libmspack/commit/18b6a2cc0b87536015bedd4f7763e6b02d5aa4f3
- https://github.com/kyz/libmspack/commit/18b6a2cc0b87536015bedd4f7763e6b02d5aa4f3
Modified: 2024-11-21
CVE-2015-4472
Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file.