CVE-2018-18586
23.10.2018, 02:29
chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application
Vendor | Product | Version |
---|---|---|
kyzer | libmspack | 0.3:alpha |
kyzer | libmspack | 0.4:alpha |
kyzer | libmspack | 0.5:alpha |
kyzer | libmspack | 0.6:alpha |
kyzer | libmspack | 0.7:alpha |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References