CVE-2015-4646Improper Input Validation in Squashfs-tools

Severity
7.5HIGHNVD
EPSS
1.0%
top 22.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 13

Description

(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

🔴Vulnerability Details

2
GHSA
GHSA-m77j-hm9g-ppq8: (1) unsquash-12022-05-13
OSV
CVE-2015-4646: (1) unsquash-12017-04-13

📋Vendor Advisories

3
Microsoft
(1) unsquash-1.c (2) unsquash-2.c (3) unsquash-3.c and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.2017-04-11
Red Hat
squashfs-tools: stack overflow in read_fragment_table_4 due to fix for CVE-2015-46452015-06-17
Debian
CVE-2015-4646: squashfs-tools - (1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Sq...2015

💬Community

2
Bugzilla
CVE-2015-4645 CVE-2015-4646 squashfs-tools: various flaws [fedora-all]2015-06-23
Bugzilla
CVE-2015-4646 squashfs-tools: stack overflow in read_fragment_table_4 due to fix for CVE-2015-46452015-06-23