CVE-2017-6419

NameCVE-2017-6419
Descriptionmspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3946-1
NVD severitymedium (attack range: remote)
Debian Bugs871263

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
clamav (PTS)wheezy0.99+dfsg-0+deb7u2vulnerable
wheezy (security)0.99.2+dfsg-0+deb7u3vulnerable
jessie0.99.2+dfsg-0+deb8u2vulnerable
stretch0.99.2+dfsg-6vulnerable
buster, sid0.99.3~beta1+dfsg-2fixed
libmspack (PTS)jessie0.5-1vulnerable
jessie (security)0.5-1+deb8u1fixed
stretch (security), stretch0.5-1+deb9u1fixed
buster, sid0.6-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
clamavsource(unstable)0.99.3~beta1+dfsg-1unimportant
libmspacksource(unstable)0.6-1medium871263
libmspacksourcejessie0.5-1+deb8u1mediumDSA-3946-1
libmspacksourcestretch0.5-1+deb9u1mediumDSA-3946-1

Notes

https://bugzilla.clamav.net/show_bug.cgi?id=11701
https://github.com/vrtadmin/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1
ClamAV uses the libmspack system library when available. This is the
case from starting from Debian Jessie. Debian Wheezy does not have
have libmspack and thus need to have the fix as well in the
src:clamav source package.
libmspack: https://github.com/kyz/libmspack/commit/6139a0b9e93fcb7fcf423e56aa825bc869e02229

Search for package or bug name: Reporting problems