CVE-2006-3178

EPSS 2.1%

chmlib - missing input sanitising

發布日:2006/6/23修改日:2026/4/28
也稱為:DEBIAN-CVE-2006-3178

描述

Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename.

受影響套件(2)

參考連結(1)