CVE Feed

    Dashboard / CVE / CVE-2018-18586

    CVE-2018-18586

    chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application

    Published:Oct 17, 2018
    Last Modified:Nov 21, 2024
    EPS:Oct 23, 2018
    EPSS Score:0.00515
    CVSS Score:5.3

    Affected Products

    Vendor
    Kyzer
    Product
    Libmspack

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High