Security Advisory
CVE-2018-18585
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has 0 as its first or second character (such as the "/0" name).