PT-2007-3400 · Acubix · Acubix Picozip

Published

2007-04-18

·

Updated

2017-07-29

·

CVE-2007-2058

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Acubix PicoZip version 4.02
Description A directory traversal issue allows user-assisted remote attackers to overwrite arbitrary files by using a .. (dot dot) sequence in the file path within certain archive types, including GZ, TAR, RAR, JAR, or ZIP archives.
Recommendations For Acubix PicoZip version 4.02, consider restricting the handling of archive files to prevent exploitation until a fix is available. As a temporary workaround, avoid using the software to extract archives from untrusted sources.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2058

Affected Products

Acubix Picozip