Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jcvf-2rhc-m6h8

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

** DISPUTED ** chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application.

** DISPUTED ** chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application.

EPSS

Процентиль: 86%
0.03011
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 8 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
redhat
почти 8 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
nvd
почти 8 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
debian
почти 8 лет назад

chmextract.c in the chmextract sample program, as distributed with lib ...

suse-cvrf
больше 4 лет назад

Security update for libmspack

EPSS

Процентиль: 86%
0.03011
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22