An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2018-14679.json"