The remote Debian host is missing a security-related update.
It was discovered that libsmpack, a library used to handle Microsoft compression formats, did not properly validate its input. A remote attacker could craft malicious CAB or CHM files and use this flaw to cause a denial of service via application crash, or potentially execute arbitrary code.
Upgrade the libmspack packages. For the oldstable distribution (jessie), these problems have been fixed in version 0.5-1+deb8u1. For the stable distribution (stretch), these problems have been fixed in version 0.5-1+deb9u1.