CVE-2018-18586

** DISPUTED ** chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kyzer:libmspack:0.3:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.7:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.6:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.5:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.4:alpha:*:*:*:*:*:*

Information

Published : 2018-10-22 19:29

Updated : 2019-04-03 05:32


NVD link : CVE-2018-18586

Mitre link : CVE-2018-18586


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

kyzer

  • libmspack