VYPR
Medium severity5.5NVD Advisory· Published Mar 17, 2017· Updated May 13, 2026

CVE-2015-4645

CVE-2015-4645

Description

Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.

Affected products

3
  • cpe:2.3:a:squashfs_project:squashfs:*:*:*:*:*:*:*:*
    Range: <=4.3
  • cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.