CVE-2018-18586
Gentoo Linux Security Advisory 201903-20
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application
** EN DISPUTA ** chmextract.c en el programa de muestra chmextract, tal y como se distribuye en libmspack en versiones anteriores a la 0.8alpha, no protege contra nombres de ruta absoluta/relativa en archivos CHM, lo que conduce a un salto de directorio. NOTA: el fabricante discute que esto sea una vulnerabilidad en libmspack, ya que chmextract.c solo se diseñó como ejemplo de código abierto, no una aplicación soportada.
An update that fixes one vulnerability is now available. This update for libmspack fixes the following issues. Fixed directory traversal in chmextract by adding anti "../" and leading slash protection.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-10-22 CVE Reserved
- 2018-10-23 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://bugs.debian.org/911639 | Mailing List | |
https://www.openwall.com/lists/oss-security/2018/10/22/1 | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://github.com/kyz/libmspack/commit/7cadd489698be117c47efcadd742651594429e6d | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201903-20 | 2024-05-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kyzer Search vendor "Kyzer" | Libmspack Search vendor "Kyzer" for product "Libmspack" | 0.3 Search vendor "Kyzer" for product "Libmspack" and version "0.3" | alpha |
Affected
| ||||||
Kyzer Search vendor "Kyzer" | Libmspack Search vendor "Kyzer" for product "Libmspack" | 0.4 Search vendor "Kyzer" for product "Libmspack" and version "0.4" | alpha |
Affected
| ||||||
Kyzer Search vendor "Kyzer" | Libmspack Search vendor "Kyzer" for product "Libmspack" | 0.5 Search vendor "Kyzer" for product "Libmspack" and version "0.5" | alpha |
Affected
| ||||||
Kyzer Search vendor "Kyzer" | Libmspack Search vendor "Kyzer" for product "Libmspack" | 0.6 Search vendor "Kyzer" for product "Libmspack" and version "0.6" | alpha |
Affected
| ||||||
Kyzer Search vendor "Kyzer" | Libmspack Search vendor "Kyzer" for product "Libmspack" | 0.7 Search vendor "Kyzer" for product "Libmspack" and version "0.7" | alpha |
Affected
|