Bug 1644216 (CVE-2018-18586) - CVE-2018-18586 libmspack: Directory traversal in chmextract.c
Summary: CVE-2018-18586 libmspack: Directory traversal in chmextract.c
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-18586
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1648376
Blocks: 1644217
TreeView+ depends on / blocked
 
Reported: 2018-10-30 09:27 UTC by Andrej Nemec
Modified: 2021-02-16 22:51 UTC (History)
6 users (show)

Fixed In Version: libmspack 0.8, cabextract 1.8
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-10 10:41:11 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2018-10-30 09:27:28 UTC
** DISPUTED ** chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application.

Upstream patch:

https://github.com/kyz/libmspack/commit/7cadd489698be117c47efcadd742651594429e6d

References:

https://www.openwall.com/lists/oss-security/2018/10/22/1

Comment 1 Stefan Cornelius 2018-11-09 15:05:54 UTC
Statement:

This issue did not affect the versions of libmspack as shipped with Red Hat Enterprise Linux 7.


Note You need to log in before you can comment on or make changes to this bug.