Skip to content

Potential Vulnerability in Cloned Code#75

Open
Mifacopy wants to merge 1 commit intojoncampbell123:masterfrom
Mifacopy:patch-1
Open

Potential Vulnerability in Cloned Code#75
Mifacopy wants to merge 1 commit intojoncampbell123:masterfrom
Mifacopy:patch-1

Conversation

@Mifacopy
Copy link
Contributor

@Mifacopy Mifacopy commented Mar 8, 2026

Summary

This PR fixes a potential security vulnerability in cloned code that appears to have missed an upstream security patch.

Details

  • Affected file: ext/libmspack/mspack/chmd.c
  • Upstream fix commit: kyz/libmspack@8759da8
  • Clone similarity score: 1.000000238418579

What this PR does

Applies the upstream security fix logic to the cloned implementation in this repository to address improper handling of malformed file names when parsing CHM headers.

References

Please review and merge this PR to ensure your repository is protected against this potential vulnerability.

Thank you for your time!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant