CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.
2025-07-04T13:15:25.453
2025-07-08T16:18:53.607
Awaiting Analysis
CVSSv3.1: 5.6 (MEDIUM)
-