CVE-2015-4472
published 2015-06-11CVE-2015-4472: Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or…
PriorityP422medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.59%
72.9th percentile
Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libmspack | < libmspack 0.5-1 (bookworm) | libmspack 0.5-1 (bookworm) |
| libmspack_project | libmspack | <= 0.4-3 | — |
| libmspack_project | libmspack | >= 0 < 0.5-1 | 0.5-1 |
| libmspack_project | libmspack | >= 0 < 0.5-1 | 0.5-1 |
| libmspack_project | libmspack | >= 0 < 0.5-1 | 0.5-1 |
| libmspack_project | libmspack | >= 0 < 0.5-1 | 0.5-1 |
| libmspack_project | libmspack | >= 0 < 0.4-1ubuntu0.1~esm2 | 0.4-1ubuntu0.1~esm2 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libmspack vulnerabilities
vendor_ubuntu·2025-10-01·CVSS 4.3
CVE-2018-14679 [MEDIUM] libmspack vulnerabilities
Title: libmspack vulnerabilities
Summary: Several security issues were fixed in libmspack.
Jakub Wilk discovered that libmspack did not correctly handle certain
integer operations and bounds checking. A remote attacker could possibly
use this issue to cause a denial of service. (CVE-2015-4467, CVE-2015-4468,
CVE-2015-4469, CVE-2015-4472)
It was discovered that libmspack incorrectly handled certain malformed CAB
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service. (CVE-2017-11423)
It was discovered that libmspack incorrectly handled certain malformed CHM
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-6419)
Hanno Böck discove
Red Hat
expat: Undefined behavior and pointer overflows
vendor_redhat·2016-05-15·CVSS 6.8
CVE-2016-4472 [MEDIUM] CWE-190 expat: Undefined behavior and pointer overflows
expat: Undefined behavior and pointer overflows
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
Package: expat (Red Hat Directory Server 8) - Under investigation
Package: apr-util (Red Hat Enterprise Linux 5) - Not affected
Package: dasher (Red Hat Enterprise Linux 5) - Not affected
Package: expat (Red Hat Enterprise Linux 5) - Will not fix
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 5) - Not affected
Package: httpd (Red Hat Enterprise Linux 5) - Not affect
Debian
CVE-2015-4472: libmspack - Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allo...
vendor_debian·2015·CVSS 6.8
CVE-2015-4472 [MEDIUM] CVE-2015-4472: libmspack - Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allo...
Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file.
Scope: local
bookworm: resolved (fixed in 0.5-1)
bullseye: resolved (fixed in 0.5-1)
forky: resolved (fixed in 0.5-1)
sid: resolved (fixed in 0.5-1)
trixie: resolved (fixed in 0.5-1)
OSV
libmspack vulnerabilities
osv·2025-10-01·CVSS 4.3
CVE-2015-4467 [MEDIUM] libmspack vulnerabilities
libmspack vulnerabilities
Jakub Wilk discovered that libmspack did not correctly handle certain
integer operations and bounds checking. A remote attacker could possibly
use this issue to cause a denial of service. (CVE-2015-4467, CVE-2015-4468,
CVE-2015-4469, CVE-2015-4472)
It was discovered that libmspack incorrectly handled certain malformed CAB
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service. (CVE-2017-11423)
It was discovered that libmspack incorrectly handled certain malformed CHM
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-6419)
Hanno Böck discovered that libmspack incorrectly handled certain CHM files.
An attac
OSV
libxmltok vulnerabilities
osv·2025-01-13·CVSS 6.8
CVE-2015-1283 libxmltok vulnerabilities
libxmltok vulnerabilities
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled certain input, whi
OSV
libxmltok vulnerabilities
osv·2022-07-19·CVSS 5.0
CVE-2012-1148 libxmltok vulnerabilities
libxmltok vulnerabilities
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2022-25235)
It was discovered
GHSA
GHSA-p84q-j7vr-6c2r: Off-by-one error in the READ_ENCINT macro in chmd
ghsa_unreviewed·2022-05-17
CVE-2015-4472 [MEDIUM] GHSA-p84q-j7vr-6c2r: Off-by-one error in the READ_ENCINT macro in chmd
Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file.
OSV
CVE-2015-4472: Off-by-one error in the READ_ENCINT macro in chmd
osv·2015-06-11·CVSS 6.8
CVE-2015-4472 [MEDIUM] CVE-2015-4472: Off-by-one error in the READ_ENCINT macro in chmd
Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CHM file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4472 expat: Undefined behavior and pointer overflows
bugzilla·2016-06-09·CVSS 6.8
CVE-2016-4472 [MEDIUM] CVE-2016-4472 expat: Undefined behavior and pointer overflows
CVE-2016-4472 expat: Undefined behavior and pointer overflows
It was found that original patch for issues CVE-2015-1283 and CVE-2015-2716 used overflow checks that could be optimized out by some compilers applying certain optimization settings, which can cause the vulnerability to remain even after applying the patch.
One pattern in the fix for CVE-2015-1283/CVE-2015-2716 is:
/* bufferSize is positive here */
do {
bufferSize *= 2;
} while (bufferSize 0);
if (bufferSize 0 as always true when the execution is defined, and bufferSize 0 out of the loop, that is, compile the code as if it had been written:
if (bufferSize <= 0)
errorCode = XML_ERROR_NO_MEMORY;
return NULL;
else {
do {
bufferSize *= 2;
} while (bufferSize < neededSize);
}
Both cases leads to not eliminating the vulnerability
Bugzilla
CVE-2015-4467 CVE-2015-4472 libmspack: denial of service while processing crafted CHM file (floating point exception)
bugzilla·2015-01-08·CVSS 4.3
CVE-2015-4467 [MEDIUM] CVE-2015-4467 CVE-2015-4472 libmspack: denial of service while processing crafted CHM file (floating point exception)
CVE-2015-4467 CVE-2015-4472 libmspack: denial of service while processing crafted CHM file (floating point exception)
It was reported [1] that libmspack crashes with SIGFPE on a crafted CHM file.
$ gpg -d sigfpe.chm
$ test/chmd_md5 sigfpe.chm
*** sigfpe.chm
d41d8cd98f00b204e9800998ecf8427e /#ITBITS
Floating point exception
Backtrace:
#0 0x5655d37b in __divdi3 ()
#1 0x56559ebb in chmd_init_decomp (file=0x56563378, self=0x56562008) at mspack/chmd.c:1132
#2 chmd_extract (base=0x56562008, file=0x56563378, filename=0x0) at mspack/chmd.c:996
#3 0x56555c40 in main (argc=2, argv=0xffffd888) at test/chmd_md5.c:44
This crashes ClamAV scanning such a file.
Proposed patch is attached.
[1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774725
Discussion:
Created attachment 977814
fix-divisi
http://openwall.com/lists/oss-security/2015/02/03/11http://www.securityfocus.com/bid/72490https://bugs.debian.org/775687https://security.gentoo.org/glsa/201506-01http://openwall.com/lists/oss-security/2015/02/03/11http://www.securityfocus.com/bid/72490https://bugs.debian.org/775687https://security.gentoo.org/glsa/201506-01
2015-06-11
Published