PT-2001-1075 · Info Zip+1 · Unzip+1

Publicado

2001-07-12

·

Atualizado

2010-05-25

·

CVE-2001-1268

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions tar versions prior to 1.13.25 UnZip versions 5.42 and earlier
Description The issue concerns multiple vulnerabilities in the tar package and a directory traversal vulnerability in Info-ZIP UnZip. These vulnerabilities can be exploited remotely, potentially leading to the integrity of protected information being compromised. The directory traversal vulnerability in UnZip allows attackers to overwrite arbitrary files during archive extraction by using a .. (dot dot) in an extracted filename.
Recommendations For tar versions prior to 1.13.25, update to a version that contains a fix for this issue. For UnZip versions 5.42 and earlier, consider disabling the archive extraction feature until a patch is available, or restrict access to the archive extraction functionality to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-08351
CVE-2001-1268

Produtos afetados

Unzip
Tar