CVE-2018-18585

Published
View on NVD ↗
CVSS v3
4.3
MEDIUM
CVSS v2
4.3
MEDIUM
Affected
1
PROJECT

Description

chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).

A library for some loosely related Microsoft compression formats, CAB, CHM, HLP, LIT, KWAJ and SZDD.
GitHubGitHub
209