CVE-2015-4472: Medium severity libmspack vulnerability
Published Jun 11, 2015
·Updated
Off-by-one error in the READENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file.
Affected Software
1 affected component
Libmspack Project Libmspack<=0.4-3
Event History
Jun 11, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4472?
CVE-2015-4472 is considered to have a moderate severity level due to its potential to cause application crashes.
2
How do I fix CVE-2015-4472?
To fix CVE-2015-4472, you should upgrade libmspack to version 0.5 or later.
3
What is the impact of CVE-2015-4472?
The impact of CVE-2015-4472 includes possible denial of service through application crashes when processing crafted CHM files.
4
Who is affected by CVE-2015-4472?
CVE-2015-4472 affects all users of libmspack versions prior to 0.5 that process CHM files.
5
Which versions of libmspack are vulnerable to CVE-2015-4472?
All versions of libmspack up to and including 0.4-3 are vulnerable to CVE-2015-4472.