Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-18586

Опубликовано: 23 окт. 2018
Источник: debian
EPSS Низкий

Описание

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libmspackfixed0.8-1package

Примечания

  • https://github.com/kyz/libmspack/commit/7cadd489698be117c47efcadd742651594429e6d

  • https://www.openwall.com/lists/oss-security/2018/10/22/1

  • src/chmextract.c was renamed from originally test/chmx.c

  • This sample code is not installed into the binary packages and was as well

  • never the idea to use it in "productised" binaries, but rather just simple

  • examples of the library use.

EPSS

Процентиль: 66%
0.00515
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
redhat
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
nvd
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

suse-cvrf
почти 4 года назад

Security update for libmspack

suse-cvrf
около 4 лет назад

Security update for libmspack

EPSS

Процентиль: 66%
0.00515
Низкий