PT-2006-4073 · Chmlib · Chmlib
Published
2006-06-23
·
Updated
2017-07-20
·
CVE-2006-3178
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CHM Lib (chmlib) versions prior to 0.38
Description
The issue concerns a directory traversal vulnerability in the extract chmLib example program. This vulnerability allows remote attackers to overwrite arbitrary files by using a CHM archive that contains files with a .. (dot dot) in their filename.
Recommendations
For versions prior to 0.38, update to version 0.38 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chmlib