CVE-2017-6419

Source
Severity Critical
Remote Yes
Type Arbitrary code execution
Description
mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV before 0.99.4, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code via a crafted CHM file.
Group Package Affected Fixed Severity Status Ticket
AVG-603 libmspack 0.5alpha-1 1:0.6alpha-1 Critical Fixed
AVG-602 clamav 0.99.3-1 0.99.4-1 Critical Fixed
Date Advisory Group Package Severity Description
18 Mar 2018 ASA-201803-14 AVG-602 clamav Critical multiple issues
20 Feb 2018 ASA-201802-9 AVG-603 libmspack Critical multiple issues
References
https://bugzilla.clamav.net/show_bug.cgi?id=11701
https://github.com/Cisco-Talos/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1
https://github.com/kyz/libmspack/commit/6139a0b9e93fcb7fcf423e56aa825bc869e02229
Notes
ClamAV uses the libmspack system library when available.