CVE-2018-18586

** DISPUTED ** chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application.
References
Configurations

Configuration 1

cpe:2.3:a:kyzer:libmspack:0.7:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.6:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.5:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.4:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.3:alpha:*:*:*:*:*:*

Information

Published : 2018-10-23 02:29

Updated : 2019-04-03 12:32


NVD link : CVE-2018-18586

Mitre link : CVE-2018-18586

Products Affected
No products.
CWE