iDefense Security Advisory 12.08.06 – Sophos AntiVirus Engine is vulnerable to a Heap Overflow attack when scanning malformed CHM archives. Specifically, if the CHM file has a Window_size of 0 set in a LZX decompression header then memory corruption will occur. Sophos Antivirus for Linux product version 4.03 and engine version 4.05 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/52913/12.08.06-3.txt
Source: https://packetstormsecurity.com/files/52913/iDEFENSE-Security-Advisory-2006-12-08.3.html

