oss-sec mailing list archives

Re: CVE Request: libmspack: frame_end overflow which could cause infinite loop


From: Salvatore Bonaccorso <carnil () debian org>
Date: Wed, 7 Jan 2015 10:47:19 +0100

Hi,

On Thu, Jan 01, 2015 at 02:12:56PM +0100, Salvatore Bonaccorso wrote:
Libmspack, a library to provide compression and decompression of
some file formats used by Microsoft, is used in many project (or
embedded there like also Clamav). This issue can cause a remotely
exploitable denial-of-service condition due to clamav thread hanging
forever while scanning the file. A patch is available at [2] for
libmspack.

I have to clarify this last part of my CVE request for libmspack. I
mentioned clamav embedding libmspack. Upstream Clamav tarball embeds
an older version of libmspack, which does not seem to be affected by
this problem. The problem itself for libmspack can be reproduced with
https://bugs.debian.org/773041#13 .

Regards,
Salvatore


Current thread: