Path traversal in libmspack - CVE-2018-18586
Published: October 23, 2018 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
** DISPUTED ** chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application.
Affected software
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
PowerStore T
Dell EMC PowerStore Family Operating System
Gentoo Linux
SUSE MicroOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
libmspack (Alpine package)
libmspack-debugsource
libmspack-devel
libmspack0
libmspack0-debuginfo
Dell EMC NetWorker vProxy
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway
RecoverPoint for VMs
How to mitigate CVE-2018-18586
libmspack (Alpine package) - update to 0.8_alpha-r0
libmspack-debugsource - addressed in versions 0.4-15.13.1, 0.6-3.14.1
libmspack-devel - addressed in versions 0.4-15.13.1, 0.6-3.14.1
libmspack0 - addressed in versions 0.4-15.13.1, 0.6-3.14.1
libmspack0-debuginfo - addressed in versions 0.4-15.13.1, 0.6-3.14.1
PowerStore T - update to 3.6.1.2-2315284
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
Dell EMC NetWorker vProxy - update to 4.3.0-40
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Dell Secure Connect Gateway - update to 5.14.00.16
RecoverPoint for VMs - update to 6.0.SP1.P1
External References
Related Security Bulletins
- Path traversal in libmspack
- Path traversal in libmspack (Alpine package)
- Gentoo update for cabextract, libmspack
- SUSE update for libmspack
- SUSE update for libmspack
- Multiple vulnerabilities in Dell Secure Connect Gateway
- SUSE update for libmspack
- Multiple vulnerabilities in Dell NetWorker vProxy
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Dell PowerStoreT OS
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines