Debian Security Advisory
DSA-4260-1 libmspack -- security update
- Date Reported:
- 02 Aug 2018
- Affected Packages:
- Security database references:
- In the Debian bugtracking system: Bug 904799, Bug 904800, Bug 904801, Bug 904802.
In Mitre's CVE dictionary: CVE-2018-14679, CVE-2018-14680, CVE-2018-14681, CVE-2018-14682.
- More information:
Several vulnerabilities were discovered in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious CAB, CHM or KWAJ files and use these flaws to cause a denial of service via application crash, or potentially execute arbitrary code.
For the stable distribution (stretch), these problems have been fixed in version 0.5-1+deb9u2.
We recommend that you upgrade your libmspack packages.
For the detailed security status of libmspack please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libmspack