PT-2018-9440 · Ruby · Rubyzip

Tuzovakaoff

·

Published

2018-06-26

·

Updated

2026-03-13

·

CVE-2018-1000544

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rubyzip versions 1.2.1 and earlier
Description The rubyzip gem contains a Directory Traversal issue in the Zip::File component, allowing an attacker to write arbitrary files to the filesystem. This can be exploited if a site allows uploading of .zip files, and an attacker uploads a malicious file containing symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.
Recommendations For rubyzip versions 1.2.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2018-1000544
DLA-1467-1
DLA-2307-1
GHSA-VQCQ-MRMW-MCMG
OPENSUSE-SU-2024:11352-1
OPENSUSE-SU-2024:13168-1
OPENSUSE-SU-2024:14176-1
OPENSUSE-SU-2025:15126-1
OPENSUSE-SU-2026:10363-1
RHSA-2018:3466

Affected Products

Rubyzip