CVE-2015-4645Integer Overflow or Wraparound in Squashfs-tools

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 56.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 13

Description

Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

Also affects: Fedora 21, 22

🔴Vulnerability Details

2
GHSA
GHSA-j67g-6r6x-5v63: Integer overflow in the read_fragment_table_4 function in unsquash-42022-05-13
OSV
CVE-2015-4645: Integer overflow in the read_fragment_table_4 function in unsquash-42017-03-17

📋Vendor Advisories

4
Microsoft
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input which trig2017-03-14
Red Hat
squashfs-tools: integer overflow in read_fragment_table_42015-06-17
Red Hat
squashfs-tools: stack overflow in read_fragment_table_4 due to fix for CVE-2015-46452015-06-17
Debian
CVE-2015-4645: squashfs-tools - Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squash...2015

💬Community

3
Bugzilla
CVE-2015-4645 squashfs-tools: integer overflow in read_fragment_table_42015-06-23
Bugzilla
CVE-2015-4645 CVE-2015-4646 squashfs-tools: various flaws [fedora-all]2015-06-23
Bugzilla
CVE-2015-4646 squashfs-tools: stack overflow in read_fragment_table_4 due to fix for CVE-2015-46452015-06-23