VulnerabilityModified
CVE-2005-2659
Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.
HIGH 10.0EPSS 2.16%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- jed wing/chm lib
- Source
- security@debian.org
References
- http://mail-index.netbsd.org/pkgsrc-changes/2005/09/12/0010.html
- http://secunia.com/advisories/17325
- http://secunia.com/advisories/17494Patch, Vendor Advisory
- http://secunia.com/advisories/17775Patch, Vendor Advisory
- http://www.debian.org/security/2005/dsa-886Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15338
- http://mail-index.netbsd.org/pkgsrc-changes/2005/09/12/0010.html
- http://secunia.com/advisories/17325
- http://secunia.com/advisories/17494Patch, Vendor Advisory
- http://secunia.com/advisories/17775Patch, Vendor Advisory
- http://www.debian.org/security/2005/dsa-886Patch, Vendor Advisory
- http://www.securityfocus.com/bid/15338
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.