PT-2018-10148 · Perl+2 · Archive/Zip+2

Cedric Buissart

·

Publicado

2018-06-29

·

Atualizado

2018-09-23

·

CVE-2018-10860

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions perl-archive-zip (affected versions not specified)
Description The issue is related to a directory traversal in Archive::Zip, where the Archive::Zip module does not properly sanitize paths while extracting zip files. This could allow an attacker to write or overwrite arbitrary files in the context of the perl interpreter by providing a specially crafted archive for processing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10860
DLA-1440-1
DSA-4300-1
MGASA-2018-0311
OPENSUSE-SU-2018_2438-1
SUSE-SU-2018:2385-1
SUSE-SU-2018:2386-1
SUSE-SU-2018:2388-1
SUSE-SU-2018_2385-1
SUSE-SU-2018_2386-1
SUSE-SU-2018_2388-1
USN-3703-1
USN-3703-2

Produtos afetados

Archive/Zip
Suse
Ubuntu