PT-2018-14530 · Libmspack+1 · Libmspack+1
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
libmspack versions prior to 0.8alpha
Description
The issue arises from the chmextract.c sample program distributed with libmspack, which fails to protect against absolute or relative pathnames in CHM files. This leads to a Directory Traversal issue. It's worth noting that the vendor disputes this being a libmspack vulnerability, as chmextract.c was intended only as a source-code example and not a supported application.
Recommendations
For versions prior to 0.8alpha, update to version 0.8alpha or later to resolve the issue. As a temporary workaround, consider restricting the use of the chmextract.c sample program until a patch is applied.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse
Libmspack