Stack-based buffer overflow in the _chm_find_in_PMGL function in chm_lib.c for chmlib before 0.36, as used in products such as KchmViewer, allows user-assisted attackers to execute arbitrary code via a CHM file containing a long element, a different vulnerability than CVE-2005-3318.
References
Link | Resource |
---|---|
http://www.idefense.com/application/poi/display?id=332&type=vulnerabilities | Patch Vendor Advisory |
http://securitytracker.com/id?1015120 | Patch Vendor Advisory |
http://secunia.com/advisories/17775 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/15234 | Patch |
http://securityreason.com/securityalert/125 | |
http://www.vupen.com/english/advisories/2005/2249 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-10-28 14:02
Updated : 2011-08-01 21:00
NVD link : CVE-2005-2930
Mitre link : CVE-2005-2930
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
jed_wing
- chm_lib