CVE-2018-18585 by Fred · 22/10/2018 chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has ‘