PT-2007-3400 · Acubix · Acubix Picozip

Publicado

2007-04-18

·

Atualizado

2017-07-29

·

CVE-2007-2058

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Acubix PicoZip version 4.02
Description A directory traversal issue allows user-assisted remote attackers to overwrite arbitrary files by using a .. (dot dot) sequence in the file path within certain archive types, including GZ, TAR, RAR, JAR, or ZIP archives.
Recommendations For Acubix PicoZip version 4.02, consider restricting the handling of archive files to prevent exploitation until a fix is available. As a temporary workaround, avoid using the software to extract archives from untrusted sources.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2058

Produtos afetados

Acubix Picozip