Описание
ELSA-2020-1178: zziplib security update (MODERATE)
[0.13.62-12]
- Fix a directory traversal bug
- unzip-mem should now strip all '../' prefixes from the archived files
- Resolves: CVE-2018-17828
Обновленные пакеты
Oracle Linux 7
Oracle Linux aarch64
zziplib
0.13.62-12.el7
zziplib-devel
0.13.62-12.el7
zziplib-utils
0.13.62-12.el7
Oracle Linux x86_64
zziplib
0.13.62-12.el7
zziplib-devel
0.13.62-12.el7
zziplib-utils
0.13.62-12.el7
Связанные CVE
Связанные уязвимости
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers ...