CVE-2018-18585
Published
CVSS v3
4.3
MEDIUM
CVSS v2
4.3
MEDIUM
Affected
1
PROJECT
Description
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
A library for some loosely related Microsoft compression formats, CAB, CHM, HLP, LIT, KWAJ and SZDD.