Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9485

Опубликовано: 16 янв. 2018
Источник: debian

Описание

Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
minizipfixed1.1-6package

Примечания

  • https://github.com/madler/zlib/commit/14a5f8f266c16c87ab6c086fc52b770b27701e01 (v1.3.1)

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.

CVSS3: 5.5
nvd
около 8 лет назад

Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.

CVSS3: 5.5
github
больше 3 лет назад

Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.