chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libmspack | Nov 29, 2018 | Oct 23, 2018 |
| Debian | — | Upgrade libmspack | Jul 30, 2024 | Oct 23, 2018 |
| Dell Powerstore Dsa2024225 | dell-powerstoreos-upgrade-latest | Jan 13, 2026 | May 29, 2024 | |
| Dell Powerstore Dsa2024287 | dell-powerstoreos-upgrade-latest | Jan 13, 2026 | Jul 2, 2024 | |
| Gentoo Linux | — | Upgrade dev-libs/libmspack.Upgrade app-arch/cabextract. | Mar 29, 2019 | Oct 22, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libmspack | Sep 16, 2021 | Oct 23, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libmspack | Apr 16, 2020 | Oct 23, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libmspack | Dec 11, 2019 | Oct 23, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libmspack | Jan 3, 2020 | Oct 23, 2018 |
| Suse | — | suse-upgrade-libmspack-develsuse-upgrade-libmspack0suse-upgrade-libmspack0-32bitsuse-upgrade-mspack-tools | Oct 31, 2018 | Oct 22, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub