High severity7.8NVD Advisory· Published Aug 7, 2017· Updated May 13, 2026
CVE-2017-6419
CVE-2017-6419
Description
mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.
Affected products
1- cpe:2.3:a:libmspack_project:libmspack:0.5:alpha:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/vrtadmin/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1nvdIssue TrackingPatchThird Party Advisory
- github.com/varsleak/varsleak-vul/blob/master/clamav-vul/heap-overflow/clamav_chm_crash.mdnvdThird Party Advisory
- bugzilla.clamav.net/show_bug.cginvdIssue Tracking
- www.debian.org/security/2017/dsa-3946nvd
- lists.debian.org/debian-lts-announce/2018/02/msg00014.htmlnvd
- security.gentoo.org/glsa/201804-16nvd
News mentions
0No linked articles in our index yet.