PT-2007-3400 · Acubix · Acubix Picozip
Published
2007-04-18
·
Updated
2017-07-29
·
CVE-2007-2058
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Acubix PicoZip version 4.02
Description
A directory traversal issue allows user-assisted remote attackers to overwrite arbitrary files by using a .. (dot dot) sequence in the file path within certain archive types, including GZ, TAR, RAR, JAR, or ZIP archives.
Recommendations
For Acubix PicoZip version 4.02, consider restricting the handling of archive files to prevent exploitation until a fix is available. As a temporary workaround, avoid using the software to extract archives from untrusted sources.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acubix Picozip