An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "clamav",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
},
{
"binary_name": "clamav-base",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
},
{
"binary_name": "clamav-daemon",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
},
{
"binary_name": "clamav-docs",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
},
{
"binary_name": "clamav-freshclam",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
},
{
"binary_name": "clamav-milter",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
},
{
"binary_name": "clamav-testfiles",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
},
{
"binary_name": "libclamav-dev",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
},
{
"binary_name": "libclamav7",
"binary_version": "0.100.1+dfsg-1ubuntu0.14.04.3"
}
]
}