Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2018-18586
Disclosure Date: October 23, 2018 (last updated November 08, 2023)
chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application
0
Attacker Value
Unknown
CVE-2018-18585
Disclosure Date: October 23, 2018 (last updated November 27, 2024)
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
0
Attacker Value
Unknown
CVE-2018-18584
Disclosure Date: October 23, 2018 (last updated November 27, 2024)
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
0
Attacker Value
Unknown
CVE-2018-14679
Disclosure Date: July 28, 2018 (last updated November 27, 2024)
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
0
Attacker Value
Unknown
CVE-2018-14682
Disclosure Date: July 28, 2018 (last updated November 27, 2024)
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
0
Attacker Value
Unknown
CVE-2018-14680
Disclosure Date: July 28, 2018 (last updated November 27, 2024)
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
0
Attacker Value
Unknown
CVE-2018-14681
Disclosure Date: July 28, 2018 (last updated November 27, 2024)
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
0