CVE-2017-11423: Medium severity libmspack vulnerability
Published Jul 18, 2017
·Updated
The cabdreadstring function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.
Affected Software
2 affected components
Libmspack Project Libmspack=0.5-alpha
clamav clamav=0.99.2
Event History
Jul 18, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11423?
The severity of CVE-2017-11423 is considered moderate due to its potential to cause denial of service.
2
How do I fix CVE-2017-11423?
To fix CVE-2017-11423, update the libmspack library to a version that is not affected by this vulnerability.
3
Who is affected by CVE-2017-11423?
CVE-2017-11423 affects users of libmspack version 0.5-alpha and ClamAV version 0.99.2.
4
What types of attacks can exploit CVE-2017-11423?
CVE-2017-11423 can be exploited by remote attackers using a specially crafted CAB file.
5
What are the potential impacts of CVE-2017-11423?
The potential impacts of CVE-2017-11423 include a stack-based buffer over-read and application crashes.