Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability

Info-ZIP UnZip contains a vulnerability during the handling of pathnames for archived files. Specifically, when certain encoded characters are inserted into '../' directory traversal sequences, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem - including paths containing system binaries and other sensitive or confidential information.

This vulnerability was reported to affect Info-ZIP UnZip 5.50 and is similar to the vulnerability described in BID 5835.







 

Privacy Statement
Copyright 2008, SecurityFocus