CVE-2015-4468: Integer Overflow
Published Jun 11, 2015
·Updated
Multiple integer overflows in the searchchunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
Affected Software
1 affected component
Libmspack Project Libmspack<=0.4-3
Event History
Jun 11, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4468?
CVE-2015-4468 has a severity rating that may lead to a denial of service due to integer overflows.
2
How does CVE-2015-4468 affect users?
CVE-2015-4468 allows remote attackers to crash applications by exploiting crafted CHM files.
3
How do I fix CVE-2015-4468?
To fix CVE-2015-4468, users should upgrade to a version of libmspack that is higher than 0.4-3.
4
What software is affected by CVE-2015-4468?
CVE-2015-4468 impacts libmspack versions prior to 0.5.
5
Is CVE-2015-4468 a client-side or server-side vulnerability?
CVE-2015-4468 is primarily a client-side vulnerability related to the handling of CHM files.