PT-2006-3080 · Magiciso · Magiciso

Sowhat

·

Published

2006-04-29

·

Updated

2018-10-18

·

CVE-2006-2100

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Magic ISO version 5.0 Build 0166
Description A directory traversal issue allows remote attackers to write arbitrary files by including a .. (dot dot) in a filename within an ISO image.
Recommendations For Magic ISO version 5.0 Build 0166, consider updating to a newer version that addresses this issue, if available. As a temporary workaround, restrict the ability to create or modify ISO images to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2100

Affected Products

Magiciso