MGASA-2017-0283

Source
https://advisories.mageia.org/MGASA-2017-0283.html
Import Source
https://advisories.mageia.org/MGASA-2017-0283.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0283
Related
Published
2017-08-19T09:58:33Z
Modified
2017-08-19T09:41:28Z
Summary
Updated libmspack packages fix security vulnerabilities
Details

It was discovered that libmspack incorrectly handled certain malformed CHM files. A remote attacker could use this issue to cause libmspack to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2017-6419).

It was discovered that libmspack incorrectly handled certain malformed CAB files. A remote attacker could use this issue to cause libmspack to crash, resulting in a denial of service (CVE-2017-11423).

References
Credits

Affected packages

Mageia:6 / libmspack

Package

Name
libmspack
Purl
pkg:rpm/mageia/libmspack?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5-0.2.alpha.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / libmspack

Package

Name
libmspack
Purl
pkg:rpm/mageia/libmspack?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5-0.1.alpha.1.mga5

Ecosystem specific

{
    "section": "core"
}