CVE-2018-18586
23.10.2018, 02:29
chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application
| Vendor | Product | Version |
|---|---|---|
| kyzer | libmspack | 0.3:alpha |
| kyzer | libmspack | 0.4:alpha |
| kyzer | libmspack | 0.5:alpha |
| kyzer | libmspack | 0.6:alpha |
| kyzer | libmspack | 0.7:alpha |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References