Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20826
HistoryJul 16, 2019 - 1:22 a.m.

Buffer Overflow

2019-07-1601:22:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

48.7%

libmspack is vulnerable to buffer overflow. The function chmd_read_headers in ibmspack/mspack/chmd.c does not handle the CHM file name properly, allowing an attacker to read past the allocated buffer if a malicious file starting with :: and length shorter than 33 bytes is provided.