Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-10860

Опубликовано: 29 июн. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 6.4
CVSS3: 5.4

Описание

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.

РелизСтатусПримечание
artful

released

1.59-1ubuntu0.1
bionic

released

1.60-1ubuntu0.1
devel

released

1.60-1ubuntu1
esm-infra-legacy/trusty

released

1.30-7ubuntu0.1
esm-infra/bionic

released

1.60-1ubuntu0.1
esm-infra/xenial

released

1.56-2ubuntu0.1
precise/esm

not-affected

1.30-6ubuntu0.1
trusty

released

1.30-7ubuntu0.1
trusty/esm

released

1.30-7ubuntu0.1
upstream

needs-triage

Показывать по

6.4 Medium

CVSS2

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
больше 7 лет назад

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.

CVSS3: 5.4
nvd
больше 7 лет назад

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.

CVSS3: 5.4
debian
больше 7 лет назад

perl-archive-zip is vulnerable to a directory traversal in Archive::Zi ...

suse-cvrf
больше 7 лет назад

Security update for perl-Archive-Zip

suse-cvrf
больше 7 лет назад

Security update for perl-Archive-Zip

6.4 Medium

CVSS2

5.4 Medium

CVSS3