libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmdreadheaders() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.
{ "vanir_signatures": [ { "signature_version": "v1", "target": { "function": "chmd_read_headers", "file": "libmspack/mspack/chmd.c" }, "signature_type": "Function", "source": "https://github.com/kyz/libmspack/commit/2f084136cfe0d05e5bf5703f3e83c6d955234b4d", "deprecated": false, "digest": { "length": 6656.0, "function_hash": "143003715646316546023193163380321845075" }, "id": "CVE-2019-1010305-07a71076" }, { "signature_version": "v1", "target": { "file": "libmspack/mspack/chmd.c" }, "signature_type": "Line", "source": "https://github.com/kyz/libmspack/commit/2f084136cfe0d05e5bf5703f3e83c6d955234b4d", "deprecated": false, "digest": { "line_hashes": [ "205328432917050020152050304626220794031", "107379853081505207412979443313635765537", "175714249841792169746246946157874795907", "103849227629512597044200399757065204356", "267909811883072031992347919703370709146", "167327124339254662897921557385068063234", "253472555009064031300059264059326324180", "21509889456730195697737899302891890500", "216385481506619540661069628206663364342", "67691593583077592570002243767481336384", "72050113466814223188819607342005960750", "24201053327704792448768183257481067363", "16869722504524110794816662320602044952", "319023267095004675747058669933082120523", "59683095410329902082271370661158293057", "96570387356960577522083627637160514080" ], "threshold": 0.9 }, "id": "CVE-2019-1010305-3fba9dab" } ] }