zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.
[
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"function": "compress",
"file": "src/lib/comp/zstd/zstd.c"
},
"deprecated": false,
"id": "CVE-2023-46228-1df40f26",
"signature_version": "v1",
"digest": {
"length": 580.0,
"function_hash": "2116317224257454294444470908301265943"
},
"signature_type": "Function"
},
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"file": "src/lib/comp/zstd/zstd.c"
},
"deprecated": false,
"id": "CVE-2023-46228-747b6bb1",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"151783038907820337332768032358069936399",
"218048448013390636466692561484580968765",
"129563666568855678901503818430373758513"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"file": "src/lib/comp/comp.c"
},
"deprecated": false,
"id": "CVE-2023-46228-81123c35",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"50891357246931241428301543661903216855",
"268537691576956652042615154783358456337",
"170538780926449768924750984331119178741"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"function": "comp_add_to_data",
"file": "src/lib/comp/comp.c"
},
"deprecated": false,
"id": "CVE-2023-46228-a1bd9b51",
"signature_version": "v1",
"digest": {
"length": 586.0,
"function_hash": "220012156912174916747493423343082481611"
},
"signature_type": "Function"
},
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"function": "read_lead",
"file": "src/lib/header.c"
},
"deprecated": false,
"id": "CVE-2023-46228-a394213e",
"signature_version": "v1",
"digest": {
"length": 3451.0,
"function_hash": "83797794204366115809677520797476196854"
},
"signature_type": "Function"
},
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"function": "read_header_from_file",
"file": "src/lib/header.c"
},
"deprecated": false,
"id": "CVE-2023-46228-b6f560c2",
"signature_version": "v1",
"digest": {
"length": 1798.0,
"function_hash": "253489117099936424379553422065609071456"
},
"signature_type": "Function"
},
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"file": "src/lib/dl/multipart.c"
},
"deprecated": false,
"id": "CVE-2023-46228-d821f501",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"230421266848289640699986192628521717271",
"89038708868757367182763429977579764585",
"131858190201161542646776539494902602956",
"60132037257554523858825685583915777398"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"file": "src/lib/header.c"
},
"deprecated": false,
"id": "CVE-2023-46228-e20d5be4",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"37353088196060664847905898572083899040",
"163255460043458710172501678537815138093",
"254515630263590307499837953728818130145",
"139931775442813519254309758815221493457",
"320406029921286300374261774297781916014",
"84563566591409761282529658102738365762",
"8963460849298768246649223443021744101",
"311903566025902104718590836131101037335",
"286400840599873318921555913118409240785",
"63216186987284058251629869691277920674"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe",
"target": {
"function": "multipart_extract",
"file": "src/lib/dl/multipart.c"
},
"deprecated": false,
"id": "CVE-2023-46228-ee0d9196",
"signature_version": "v1",
"digest": {
"length": 2334.0,
"function_hash": "264856671191392251456041341874161471918"
},
"signature_type": "Function"
}
]