PT-2005-1259 · Unace · Unace
Published
2005-02-22
·
Updated
2008-09-05
·
CVE-2005-0161
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
unace version 1.2b
Description
The issue allows attackers to overwrite arbitrary files via an ACE archive containing ../ sequences or absolute pathnames, potentially leading to unauthorized file modifications.
Recommendations
For unace version 1.2b, consider avoiding the use of ACE archives that contain ../ sequences or absolute pathnames until a patch is available. As a temporary workaround, restrict the ability to create or modify ACE archives to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unace