CVE-2006-3178
EPSS 2.1%chmlib - missing input sanitising
發布日:2006/6/23修改日:2026/4/28
也稱為:DEBIAN-CVE-2006-3178
描述
Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename.
受影響套件(2)
- Debian/chmlibfrom 0, < 0.38-1
- Debian/chmlibfrom 0, < 0.35-6sarge3