| Severity |
|
| Remote |
|
| Type |
| + |
Arbitrary code execution |
|
| Description |
| + |
mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV before 0.99.4, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code via a crafted CHM file. |
|
| References |
| + |
https://bugzilla.clamav.net/show_bug.cgi?id=11701 |
| + |
https://github.com/Cisco-Talos/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1 |
| + |
https://github.com/kyz/libmspack/commit/6139a0b9e93fcb7fcf423e56aa825bc869e02229 |
|
| Notes |
| + |
ClamAV uses the libmspack system library when available. |
|