Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1002200

Опубликовано: 25 июл. 2018
Источник: debian
EPSS Низкий

Описание

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
plexus-archiverfixed3.6.0-1package

Примечания

  • https://github.com/codehaus-plexus/plexus-archiver/pull/87

  • https://github.com/codehaus-plexus/plexus-archiver/commit/58bc24e465c0842981692adbf6d75680298989de

EPSS

Процентиль: 83%
0.01901
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 7.3
redhat
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 5.5
nvd
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 5.5
github
больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in plexus-archiver

oracle-oval
больше 7 лет назад

ELSA-2018-1836: plexus-archiver security update (IMPORTANT)

EPSS

Процентиль: 83%
0.01901
Низкий