PT-2004-1119 · Unarj · Unarj

Published

2004-11-16

·

Updated

2023-10-30

·

CVE-2004-1027

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions unarj (affected versions not specified)
Description The issue is related to a directory traversal vulnerability in the -x (extract) command line option. This vulnerability allows remote attackers to overwrite arbitrary files by using an arj archive with filenames that contain .. (dot dot) sequences. The vulnerability is associated with insufficient path restriction, enabling an attacker to exploit it and overwrite files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2017-00281
CVE-2004-1027
DSA-652-1
MGASA-2023-0107

Affected Products

Unarj