Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqcq-mrmw-mcmg

Опубликовано: 06 сент. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Rubyzip gem contains a Directory Traversal vulnerability in zip file component

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..

This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete.

Пакеты

Наименование

rubyzip

rubygems
Затронутые версииВерсия исправления

<= 1.2.1

1.2.2

EPSS

Процентиль: 71%
0.00681
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434
CWE-59

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..

CVSS3: 4.8
redhat
больше 7 лет назад

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..

CVSS3: 9.8
nvd
больше 7 лет назад

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..

CVSS3: 9.8
debian
больше 7 лет назад

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Tra ...

EPSS

Процентиль: 71%
0.00681
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434
CWE-59