|
Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability
Info-ZIP UnZip contains a vulnerability during the handling of pathnames for archived files. Specifically, when certain encoded characters are inserted into '../' directory traversal sequences, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem - including paths containing system binaries and other sensitive or confidential information. This vulnerability was reported to affect Info-ZIP UnZip 5.50 and is similar to the vulnerability described in BID 5835. |
|
|
Privacy Statement |