Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:2385-1

Опубликовано: 16 авг. 2018
Источник: suse-cvrf

Описание

Security update for perl-Archive-Zip

This update for perl-Archive-Zip fixes the following security issue:

  • CVE-2018-10860: Prevent directory traversal caused by not properly sanitizing paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could have used this flaw to write or overwrite arbitrary files in the context of the perl interpreter (bsc#1099497)

Список пакетов

SUSE Linux Enterprise Desktop 12 SP3
perl-Archive-Zip-1.34-3.3.1
SUSE Linux Enterprise Server 12 SP3
perl-Archive-Zip-1.34-3.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
perl-Archive-Zip-1.34-3.3.1

Описание

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP3:perl-Archive-Zip-1.34-3.3.1
SUSE Linux Enterprise Server 12 SP3:perl-Archive-Zip-1.34-3.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3:perl-Archive-Zip-1.34-3.3.1

Ссылки