PT-2018-10148 · Perl+2 · Archive/Zip+2

Cedric Buissart

·

Published

2018-06-29

·

Updated

2018-09-23

·

CVE-2018-10860

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions perl-archive-zip (affected versions not specified)
Description The issue is related to a directory traversal in Archive::Zip, where the Archive::Zip module does not properly sanitize paths while extracting zip files. This could allow an attacker to write or overwrite arbitrary files in the context of the perl interpreter by providing a specially crafted archive for processing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10860
DLA-1440-1
DSA-4300-1
MGASA-2018-0311
OPENSUSE-SU-2018_2438-1
SUSE-SU-2018:2385-1
SUSE-SU-2018:2386-1
SUSE-SU-2018:2388-1
SUSE-SU-2018_2385-1
SUSE-SU-2018_2386-1
SUSE-SU-2018_2388-1
USN-3703-1
USN-3703-2

Affected Products

Archive/Zip
Suse
Ubuntu