CVE-2018-18586: Path Traversal
DISPUTED chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18586?
CVE-2018-18586 is a vulnerability in the chmextract sample program, as distributed with libmspack before 0.8alpha, that allows for Directory Traversal.
Is CVE-2018-18586 a libmspack vulnerability?
The vendor disputes that CVE-2018-18586 is a libmspack vulnerability.
What is the severity of CVE-2018-18586?
The severity of CVE-2018-18586 is medium, with a severity value of 5.3.
How does CVE-2018-18586 affect Kyzer Libmspack?
CVE-2018-18586 affects Kyzer Libmspack versions 0.3-alpha to 0.7-alpha.
How can I fix CVE-2018-18586?
To fix CVE-2018-18586, it is recommended to upgrade to libmspack version 0.8alpha or later.