Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-1836

Опубликовано: 12 июн. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-1836: plexus-archiver security update (IMPORTANT)

[0:2.4.2-5]

  • Fix arbitrary file write vulnerability
  • Resolves: CVE-2018-1002200

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

plexus-archiver

2.4.2-5.el7_5

plexus-archiver-javadoc

2.4.2-5.el7_5

Oracle Linux x86_64

plexus-archiver

2.4.2-5.el7_5

plexus-archiver-javadoc

2.4.2-5.el7_5

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 7.3
redhat
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 5.5
nvd
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 5.5
debian
больше 7 лет назад

plexus-archiver before 3.6.0 is vulnerable to directory traversal, all ...

CVSS3: 5.5
github
больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in plexus-archiver