6.4
CVSSv2

CVE-2002-1425

Published: 11/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in munpack in mpack 1.5 and previous versions allows remote malicious users to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.

Vulnerable Product Search on Vulmon Subscribe to Product

john g. myers mpack

Vendor Advisories

Eckehard Berns discovered a buffer overflow in the munpack program which is used for decoding (respectively) binary files in MIME (Multipurpose Internet Mail Extensions) format mail messages If munpack is run on an appropriately malformed email (or news article) then it will crash, and perhaps can be made to run arbitrary code Herbert Xu reported ...