|
Message-ID: <20150203155205.GA14955@eldamar.local> Date: Tue, 3 Feb 2015 16:52:05 +0100 From: Salvatore Bonaccorso <carnil@...ian.org> To: OSS Security Mailinglist <oss-security@...ts.openwall.com> Cc: CVE Assignments MITRE <cve-assign@...re.org> Subject: Possible CVE Requests: libmspack: several issues Hi Several issues with the libmspack library were reported recently in the Debian bugtracker by Jakub Wilk. An (older) copy of libmspack is also embedded in ClamAV (not verified if this version is also affected by these issues). The reported bugs are the following: null pointer dereference on a crafted CAB: - https://bugs.debian.org/774665 CHM decompression: division by zero - https://bugs.debian.org/774725 CHM decompression: pointer arithmetic overflow - https://bugs.debian.org/774726 off-by-one buffer over-read in mspack/mszipd.c - https://bugs.debian.org/775498 off-by-one buffer under-read in mspack/lzxd.c - https://bugs.debian.org/775499 CHM decompression: another pointer arithmetic overflow - https://bugs.debian.org/775687 Could CVEs be assigned for these issues? Regards, Salvatore
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.