PT-2014-4397 · Company · R-Company Unzipper

Published

2014-03-18

·

Updated

2015-07-30

·

CVE-2014-1975

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions R-Company Unzipper versions 1.0.1 and earlier
Description The issue allows remote attackers to overwrite or create arbitrary files via a crafted filename, potentially leading to unauthorized access or data modification.
Recommendations For versions 1.0.1 and earlier, update to a version that contains a fix for this issue, as no specific workaround is provided for these versions.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1975

Affected Products

R-Company Unzipper