libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmdreadheaders() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.
[
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "143003715646316546023193163380321845075",
"length": 6656.0
},
"id": "CVE-2019-1010305-07a71076",
"source": "https://github.com/kyz/libmspack/commit/2f084136cfe0d05e5bf5703f3e83c6d955234b4d",
"target": {
"function": "chmd_read_headers",
"file": "libmspack/mspack/chmd.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"205328432917050020152050304626220794031",
"107379853081505207412979443313635765537",
"175714249841792169746246946157874795907",
"103849227629512597044200399757065204356",
"267909811883072031992347919703370709146",
"167327124339254662897921557385068063234",
"253472555009064031300059264059326324180",
"21509889456730195697737899302891890500",
"216385481506619540661069628206663364342",
"67691593583077592570002243767481336384",
"72050113466814223188819607342005960750",
"24201053327704792448768183257481067363",
"16869722504524110794816662320602044952",
"319023267095004675747058669933082120523",
"59683095410329902082271370661158293057",
"96570387356960577522083627637160514080"
]
},
"id": "CVE-2019-1010305-3fba9dab",
"source": "https://github.com/kyz/libmspack/commit/2f084136cfe0d05e5bf5703f3e83c6d955234b4d",
"target": {
"file": "libmspack/mspack/chmd.c"
}
}
]