Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.
References
Configurations
History
No history.
Information
Published : 2001-07-12 04:00
Updated : 2010-05-25 04:10
NVD link : CVE-2001-1268
Mitre link : CVE-2001-1268
CVE.ORG link : CVE-2001-1268
JSON object : View
Products Affected
info-zip
- unzip
CWE