5
CVSSv2

CVE-2006-3178

Published: 23/06/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) prior to 0.38 allows remote malicious users to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename.

Vulnerable Product Search on Vulmon Subscribe to Product

jed wing chm lib

Vendor Advisories

It was discovered that one of the utilities shipped with chmlib, a library for dealing with Microsoft CHM files, performs insufficient sanitising of filenames, which might lead to directory traversal For the stable distribution (sarge) this problem has been fixed in version 035-6sarge3 For the unstable distribution (sid) this problem has been fi ...