CVE-2005-2930

critical

Description

Stack-based buffer overflow in the _chm_find_in_PMGL function in chm_lib.c for chmlib before 0.36, as used in products such as KchmViewer, allows user-assisted attackers to execute arbitrary code via a CHM file containing a long element, a different vulnerability than CVE-2005-3318.

References

http://www.vupen.com/english/advisories/2005/2249

http://www.securityfocus.com/bid/15234

http://www.idefense.com/application/poi/display?id=332&type=vulnerabilities

http://securitytracker.com/id?1015120

http://securityreason.com/securityalert/125

http://secunia.com/advisories/17775

Details

Source: Mitre, NVD

Published: 2005-10-28

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 5.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical