Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18586

Опубликовано: 23 окт. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kyzer:libmspack:0.3:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.4:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.5:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.6:alpha:*:*:*:*:*:*
cpe:2.3:a:kyzer:libmspack:0.7:alpha:*:*:*:*:*:*

EPSS

Процентиль: 66%
0.00515
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
redhat
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
debian
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with lib ...

suse-cvrf
почти 4 года назад

Security update for libmspack

suse-cvrf
около 4 лет назад

Security update for libmspack

EPSS

Процентиль: 66%
0.00515
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22