libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmdreadheaders() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.
{ "vanir_signatures": [ { "digest": { "function_hash": "143003715646316546023193163380321845075", "length": 6656.0 }, "id": "CVE-2019-1010305-07a71076", "source": "https://github.com/kyz/libmspack/commit/2f084136cfe0d05e5bf5703f3e83c6d955234b4d", "signature_type": "Function", "signature_version": "v1", "target": { "file": "libmspack/mspack/chmd.c", "function": "chmd_read_headers" }, "deprecated": false }, { "digest": { "threshold": 0.9, "line_hashes": [ "205328432917050020152050304626220794031", "107379853081505207412979443313635765537", "175714249841792169746246946157874795907", "103849227629512597044200399757065204356", "267909811883072031992347919703370709146", "167327124339254662897921557385068063234", "253472555009064031300059264059326324180", "21509889456730195697737899302891890500", "216385481506619540661069628206663364342", "67691593583077592570002243767481336384", "72050113466814223188819607342005960750", "24201053327704792448768183257481067363", "16869722504524110794816662320602044952", "319023267095004675747058669933082120523", "59683095410329902082271370661158293057", "96570387356960577522083627637160514080" ] }, "id": "CVE-2019-1010305-3fba9dab", "source": "https://github.com/kyz/libmspack/commit/2f084136cfe0d05e5bf5703f3e83c6d955234b4d", "signature_type": "Line", "signature_version": "v1", "target": { "file": "libmspack/mspack/chmd.c" }, "deprecated": false } ] }