CVE-2019-1010305: Canonical Ubuntu Linux

Medium severity, CVSS 5.5. EPSS: 1.5% chance of exploitation in the next 30 days.

libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • Kyzer Libmspack: version 0.9.1 only

Published 2019-07-15. Last modified 2026-06-17.