Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename. Upgrade to version 0.38
Publication date: Fri, 23 Jun 2006 05:02:00 +0000