CVE-2017-6419: Libmspack Project Libmspack

High severity, CVSS 7.8. EPSS: 2% chance of exploitation in the next 30 days.

mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

Affected products

Published 2017-08-07. Last modified 2026-06-17.