Errata ID | 319 |
---|---|
Date | 2018-11-21 |
Source package | libmspack |
Fixed in version | 0.5-1.A~4.3.2.201811191242 |
Description | This update addresses the following issues: * heap-based buffer overflow in mspack/lzxd.c (CVE-2017-6419) * Stack-based buffer over-read in cabd_read_string function (CVE-2017-11423) * off-by-one error in the CHM PMGI/PMGL chunk number validity checks (CVE-2018-14679) * off-by-one error in the CHM chunk number validity checks (CVE-2018-14680) * Out-of-bounds Write in kwajd_read_headers in mspack/kwajd.c (CVE-2018-14681) * off-by-one error in the TOLOWER() macro for CHM decompression (CVE-2018-14682) * Out-of-bounds write in mspack/cab.h (CVE-2018-18584) * chmd_read_headers() fails to reject filenames containing NULL bytes (CVE-2018-18585) |
Additional notes | |
CVE ID | CVE-2017-6419 CVE-2017-11423 CVE-2018-14679 CVE-2018-14680 CVE-2018-14681 CVE-2018-14682 CVE-2018-18584 CVE-2018-18585 |
UCS Bug number | #48168 |