chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-libmspack | Nov 29, 2018 | Oct 23, 2018 | |
| Debian | debian-upgrade-libmspack | Jul 30, 2024 | Oct 23, 2018 | |
| Dell Powerstore Dsa2024225 | dell-powerstoreos-upgrade-latest | Jan 13, 2026 | May 29, 2024 | |
| Dell Powerstore Dsa2024287 | dell-powerstoreos-upgrade-latest | Jan 13, 2026 | Jul 2, 2024 | |
| Gentoo Linux | gentoo-linux-upgrade-app-arch-cabextractgentoo-linux-upgrade-dev-libs-libmspack | Mar 29, 2019 | Oct 22, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libmspack | Sep 16, 2021 | Oct 23, 2018 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-libmspack | Apr 16, 2020 | Oct 23, 2018 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-libmspack | Dec 11, 2019 | Oct 23, 2018 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-libmspack | Jan 3, 2020 | Oct 23, 2018 | |
| Suse | — | suse-upgrade-libmspack-develsuse-upgrade-libmspack0suse-upgrade-libmspack0-32bitsuse-upgrade-mspack-tools | Oct 31, 2018 | Oct 22, 2018 |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Oct 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub