{"id":"CVE-2018-18586","details":"chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application","modified":"2026-05-17T11:55:12.488964997Z","published":"2018-10-23T02:29:00.700Z","related":["SUSE-SU-2022:0069-1","SUSE-SU-2022:0069-2","SUSE-SU-2022:4287-1","openSUSE-SU-2022:0069-1","openSUSE-SU-2024:13619-1"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://bugs.debian.org/911639"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201903-20"},{"type":"ADVISORY","url":"https://www.openwall.com/lists/oss-security/2018/10/22/1"},{"type":"EVIDENCE","url":"https://github.com/kyz/libmspack/commit/7cadd489698be117c47efcadd742651594429e6d"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}