Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-18586

Опубликовано: 17 окт. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

Отчет

This issue did not affect the versions of libmspack as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libmspackNot affected
Red Hat Enterprise Linux 8libmspackNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1644216libmspack: Directory traversal in chmextract.c

EPSS

Процентиль: 66%
0.00515
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
nvd
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

CVSS3: 5.3
debian
больше 7 лет назад

chmextract.c in the chmextract sample program, as distributed with lib ...

suse-cvrf
почти 4 года назад

Security update for libmspack

suse-cvrf
около 4 лет назад

Security update for libmspack

EPSS

Процентиль: 66%
0.00515
Низкий

5.3 Medium

CVSS3