mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.
[
{
"deprecated": false,
"target": {
"file": "libclamav/libmspack.c",
"function": "mspack_fmap_free"
},
"signature_type": "Function",
"source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1",
"signature_version": "v1",
"id": "CVE-2017-6419-158e5c12",
"digest": {
"function_hash": "105314170104537119795892195005646536883",
"length": 64.0
}
},
{
"deprecated": false,
"target": {
"file": "libclamav/libmspack-0.5alpha/mspack/lzxd.c",
"function": "lzxd_free"
},
"signature_type": "Function",
"source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1",
"signature_version": "v1",
"id": "CVE-2017-6419-2dff9d70",
"digest": {
"function_hash": "36425859503893486122199183962679951196",
"length": 179.0
}
},
{
"deprecated": false,
"target": {
"file": "libclamav/libmspack-0.5alpha/mspack/lzxd.c"
},
"signature_type": "Line",
"source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1",
"signature_version": "v1",
"id": "CVE-2017-6419-3c94d9a1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"136812049944724980978743740024966289697",
"239642238586611879435853196125623206467",
"40883855409387376279425001697949305055",
"207670088480332678768897160205840489720",
"137050635423474274304079970391599644070",
"256192828004486556560188961880269201204",
"92030697883542239907420004418267516576",
"133434634387658503944555526626693766626",
"57477167490934286654239258003596752208",
"299735408700367508640607568273422838006"
]
}
},
{
"deprecated": false,
"target": {
"file": "libclamav/libmspack.c"
},
"signature_type": "Line",
"source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1",
"signature_version": "v1",
"id": "CVE-2017-6419-565b7fba",
"digest": {
"threshold": 0.9,
"line_hashes": [
"39213307635245385338061781708479438537",
"161293350000683804664213130242652150668",
"179719491279128692184227813514265352406",
"111485140398853709928158643894428398984"
]
}
},
{
"deprecated": false,
"target": {
"file": "libclamav/libmspack-0.5alpha/mspack/lzxd.c",
"function": "lzxd_decompress"
},
"signature_type": "Function",
"source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1",
"signature_version": "v1",
"id": "CVE-2017-6419-d5ca588a",
"digest": {
"function_hash": "157883946808374614544341957531013484112",
"length": 10410.0
}
}
]