CVE-2015-4468
published 2015-06-11CVE-2015-4468: Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.46%
70.6th percentile
Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libmspack | < libmspack 0.4-3 (bookworm) | libmspack 0.4-3 (bookworm) |
| libmspack_project | libmspack | <= 0.4-3 | — |
| libmspack_project | libmspack | >= 0 < 0.4-3 | 0.4-3 |
| libmspack_project | libmspack | >= 0 < 0.4-3 | 0.4-3 |
| libmspack_project | libmspack | >= 0 < 0.4-3 | 0.4-3 |
| libmspack_project | libmspack | >= 0 < 0.4-3 | 0.4-3 |
| libmspack_project | libmspack | >= 0 < 0.4-1ubuntu0.1~esm2 | 0.4-1ubuntu0.1~esm2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libmspack vulnerabilities
vendor_ubuntu·2025-10-01·CVSS 4.3
CVE-2018-14679 [MEDIUM] libmspack vulnerabilities
Title: libmspack vulnerabilities
Summary: Several security issues were fixed in libmspack.
Jakub Wilk discovered that libmspack did not correctly handle certain
integer operations and bounds checking. A remote attacker could possibly
use this issue to cause a denial of service. (CVE-2015-4467, CVE-2015-4468,
CVE-2015-4469, CVE-2015-4472)
It was discovered that libmspack incorrectly handled certain malformed CAB
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service. (CVE-2017-11423)
It was discovered that libmspack incorrectly handled certain malformed CHM
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-6419)
Hanno Böck discove
Debian
CVE-2015-4468: libmspack - Multiple integer overflows in the search_chunk function in chmd.c in libmspack b...
vendor_debian·2015·CVSS 4.3
CVE-2015-4468 [MEDIUM] CVE-2015-4468: libmspack - Multiple integer overflows in the search_chunk function in chmd.c in libmspack b...
Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
Scope: local
bookworm: resolved (fixed in 0.4-3)
bullseye: resolved (fixed in 0.4-3)
forky: resolved (fixed in 0.4-3)
sid: resolved (fixed in 0.4-3)
trixie: resolved (fixed in 0.4-3)
OSV
libmspack vulnerabilities
osv·2025-10-01·CVSS 4.3
CVE-2015-4467 [MEDIUM] libmspack vulnerabilities
libmspack vulnerabilities
Jakub Wilk discovered that libmspack did not correctly handle certain
integer operations and bounds checking. A remote attacker could possibly
use this issue to cause a denial of service. (CVE-2015-4467, CVE-2015-4468,
CVE-2015-4469, CVE-2015-4472)
It was discovered that libmspack incorrectly handled certain malformed CAB
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service. (CVE-2017-11423)
It was discovered that libmspack incorrectly handled certain malformed CHM
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-6419)
Hanno Böck discovered that libmspack incorrectly handled certain CHM files.
An attac
GHSA
GHSA-f6cg-9mvp-r5gc: Multiple integer overflows in the search_chunk function in chmd
ghsa_unreviewed·2022-05-17
CVE-2015-4468 [MEDIUM] GHSA-f6cg-9mvp-r5gc: Multiple integer overflows in the search_chunk function in chmd
Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
OSV
CVE-2015-4468: Multiple integer overflows in the search_chunk function in chmd
osv·2015-06-11·CVSS 4.3
CVE-2015-4468 [MEDIUM] CVE-2015-4468: Multiple integer overflows in the search_chunk function in chmd
Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CHM file.
No detection rules found.
No public exploits indexed.
http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-pointer-arithmetic-overflow.patch?id=a25bb144795e526748b57884daf365732c7e2295http://openwall.com/lists/oss-security/2015/02/03/11http://www.securityfocus.com/bid/72486https://bugs.debian.org/774726http://anonscm.debian.org/cgit/collab-maint/libmspack.git/diff/debian/patches/fix-pointer-arithmetic-overflow.patch?id=a25bb144795e526748b57884daf365732c7e2295http://openwall.com/lists/oss-security/2015/02/03/11http://www.securityfocus.com/bid/72486https://bugs.debian.org/774726
2015-06-11
Published