2.6
CVSSv2

CVE-2003-0282

Published: 16/06/2003 Updated: 11/10/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in UnZip 5.50 allows malicious users to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

info-zip unzip 5.50

sco openlinux workstation 3.1.1

sco openlinux server 3.1.1

Vendor Advisories

A directory traversal vulnerability in UnZip 550 allows attackers to bypass a check for relative pathnames ("/") by placing certain invalid characters between the two "" characters The fix which was implemented in DSA-344-1 may not have protected against all methods of exploiting this vulnerability For the stable distribution (woody) this pro ...

Exploits

source: wwwsecurityfocuscom/bid/7550/info Info-ZIP UnZip contains a vulnerability during the handling of pathnames for archived files Specifically, when certain encoded characters are inserted into '/' directory traversal sequences, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem - ...