Name | CVE-2017-6419 |
Description | mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1279-1, DSA-3946-1 |
Debian Bugs | 871263 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
clamav (PTS) | jessie, jessie (lts) | 0.103.9+dfsg-0+deb8u1 | fixed |
| stretch (security) | 0.103.6+dfsg-0+deb9u1 | fixed |
| stretch (lts), stretch | 0.103.9+dfsg-0+deb9u1 | fixed |
| buster (security), buster, buster (lts) | 0.103.9+dfsg-0+deb10u1 | fixed |
| bullseye | 0.103.10+dfsg-0+deb11u1 | fixed |
| bookworm | 1.0.7+dfsg-1~deb12u1 | fixed |
| sid, trixie | 1.4.1+dfsg-1 | fixed |
libmspack (PTS) | jessie, jessie (lts) | 0.5-1+deb8u4 | fixed |
| stretch (security), stretch (lts), stretch | 0.5-1+deb9u4 | fixed |
| buster | 0.10.1-1 | fixed |
| bullseye | 0.10.1-2 | fixed |
| bookworm | 0.11-1 | fixed |
| sid, trixie | 0.11-1.1 | fixed |
The information below is based on the following data on fixed versions.
Notes
https://bugzilla.clamav.net/show_bug.cgi?id=11701
https://github.com/vrtadmin/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1
ClamAV uses the libmspack system library when available. This is the
case from starting from Debian Jessie. Debian Wheezy does not have
have libmspack and thus need to have the fix as well in the
src:clamav source package.
libmspack: https://github.com/kyz/libmspack/commit/6139a0b9e93fcb7fcf423e56aa825bc869e02229