CVE-2006-3178
EPSS 2.1%chmlib - missing input sanitising
Published: 6/23/2006Modified: 4/28/2026
Also known as:DEBIAN-CVE-2006-3178
Description
Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename.
Affected packages (2)
- Debian/chmlibfrom 0, < 0.38-1
- Debian/chmlibfrom 0, < 0.35-6sarge3