PT-2018-14530 · Libmspack+1 · Libmspack+1

·

CVE-2018-18586

·

Publicado

2018-10-23

·

Atualizado

2024-08-05

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions libmspack versions prior to 0.8alpha
Description The issue arises from the chmextract.c sample program distributed with libmspack, which fails to protect against absolute or relative pathnames in CHM files. This leads to a Directory Traversal issue. It's worth noting that the vendor disputes this being a libmspack vulnerability, as chmextract.c was intended only as a source-code example and not a supported application.
Recommendations For versions prior to 0.8alpha, update to version 0.8alpha or later to resolve the issue. As a temporary workaround, consider restricting the use of the chmextract.c sample program until a patch is applied.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18586
MGASA-2018-0455
OPENSUSE-SU-2022:0069-1
OPENSUSE-SU-2022_0069-1
OPENSUSE-SU-2022_0069-2
OPENSUSE-SU-2024:13619-1
SUSE-SU-2022:0069-1
SUSE-SU-2022:0069-2
SUSE-SU-2022:4287-1
SUSE-SU-2022_0069-1
SUSE-SU-2022_4287-1

Produtos afetados

Suse
Libmspack