Back to Database
Status published
Medium
CVE-2015-4470
Off-by-one error in the inflate function in mszipd.c in libmspack...
Vulnerability Description
Off-by-one error in the inflate function in mszipd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CAB archive.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-4470
Credits & Attribution
No credits recorded in the NVD database.
References
More from libmspack project
View All →CVE-2017-6419
mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows...
High
7.8
CVE-2017-11423
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used...
Medium
5.5
CVE-2015-4472
Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack...
Medium
6.8
CVE-2015-4471
Off-by-one error in the lzxd_decompress function in lzxd.c in libmspack...
Medium
4.3
CVE-2015-4469
The chmd_read_headers function in chmd.c in libmspack before 0.5 does...
Medium
4.3
Affected Vendor
libmspack project
View all reports →Affected Software
libmspack
Vulnerable Versions:
0
Timeline
Official Publish:
June 11th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.