UBUNTU-CVE-2017-6419
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-6419
UBUNTU-CVE-2017-6419
Summary:
Details: mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.
References: https://ubuntu.com/security/CVE-2017-6419, https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/heap-overflow/clamav_chm_crash.md, https://ubuntu.com/security/notices/USN-3394-1, https://ubuntu.com/security/notices/USN-3393-1, https://ubuntu.com/security/notices/USN-3393-2, https://www.cve.org/CVERecord?id=CVE-2017-6419, https://ubuntu.com/security/notices/USN-7788-1
Affected packages
Package
Name: clamav
Purl: pkg:deb/ubuntu/[email protected]+addedllvm-0ubuntu0.14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
