Vulnerabilities > CVE-2006-3178 - Unspecified vulnerability in JED Wing CHM LIB
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN jed-wing
nessus
Summary
Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1144.NASL |
description | It was discovered that one of the utilities shipped with chmlib, a library for dealing with Microsoft CHM files, performs insufficient sanitising of filenames, which might lead to directory traversal. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22686 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22686 |
title | Debian DSA-1144-1 : chmlib - missing input sanitising |
References
- http://morte.jedrea.com/~jedwin/projects/chmlib/
- http://morte.jedrea.com/~jedwin/projects/chmlib/
- http://secunia.com/advisories/20734
- http://secunia.com/advisories/20734
- http://secunia.com/advisories/21406
- http://secunia.com/advisories/21406
- http://securitytracker.com/id?1016343
- http://securitytracker.com/id?1016343
- http://www.debian.org/security/2006/dsa-1144
- http://www.debian.org/security/2006/dsa-1144
- http://www.osvdb.org/26636
- http://www.osvdb.org/26636
- http://www.securityfocus.com/bid/18511
- http://www.securityfocus.com/bid/18511
- http://www.vupen.com/english/advisories/2006/2430
- http://www.vupen.com/english/advisories/2006/2430
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27278
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27278