mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.
{ "vanir_signatures": [ { "signature_type": "Function", "signature_version": "v1", "source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1", "deprecated": false, "id": "CVE-2017-6419-158e5c12", "target": { "function": "mspack_fmap_free", "file": "libclamav/libmspack.c" }, "digest": { "length": 64.0, "function_hash": "105314170104537119795892195005646536883" } }, { "signature_type": "Function", "signature_version": "v1", "source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1", "deprecated": false, "id": "CVE-2017-6419-2dff9d70", "target": { "function": "lzxd_free", "file": "libclamav/libmspack-0.5alpha/mspack/lzxd.c" }, "digest": { "length": 179.0, "function_hash": "36425859503893486122199183962679951196" } }, { "signature_type": "Line", "signature_version": "v1", "source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1", "deprecated": false, "id": "CVE-2017-6419-3c94d9a1", "target": { "file": "libclamav/libmspack-0.5alpha/mspack/lzxd.c" }, "digest": { "line_hashes": [ "136812049944724980978743740024966289697", "239642238586611879435853196125623206467", "40883855409387376279425001697949305055", "207670088480332678768897160205840489720", "137050635423474274304079970391599644070", "256192828004486556560188961880269201204", "92030697883542239907420004418267516576", "133434634387658503944555526626693766626", "57477167490934286654239258003596752208", "299735408700367508640607568273422838006" ], "threshold": 0.9 } }, { "signature_type": "Line", "signature_version": "v1", "source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1", "deprecated": false, "id": "CVE-2017-6419-565b7fba", "target": { "file": "libclamav/libmspack.c" }, "digest": { "line_hashes": [ "39213307635245385338061781708479438537", "161293350000683804664213130242652150668", "179719491279128692184227813514265352406", "111485140398853709928158643894428398984" ], "threshold": 0.9 } }, { "signature_type": "Function", "signature_version": "v1", "source": "https://github.com/cisco-talos/clamav/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1", "deprecated": false, "id": "CVE-2017-6419-d5ca588a", "target": { "function": "lzxd_decompress", "file": "libclamav/libmspack-0.5alpha/mspack/lzxd.c" }, "digest": { "length": 10410.0, "function_hash": "157883946808374614544341957531013484112" } } ] }