PT-2018-14529 · Microsoft+4 · Libmspack+4
Hanno Böck
·
Published
2018-10-22
·
Updated
2025-10-01
·
CVE-2018-18585
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
libmspack versions prior to 0.8alpha
Description
The issue arises from the
chmd read headers function in mspack/chmd.c, which improperly handles filenames starting with '0' as their first or second character. This could potentially lead to unintended behavior when processing such filenames.Recommendations
For versions prior to 0.8alpha, update to version 0.8alpha or later to resolve the issue.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Ubuntu
Libmspack