5
CVSSv2

CVE-2004-0916

Published: 27/01/2005 Updated: 26/04/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in cabextract prior to 1.1 allows remote malicious users to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cabextract project cabextract 0.2

cabextract project cabextract 0.6

cabextract project cabextract 1.0

Vendor Advisories

The upstream developers discovered a problem in cabextract, a tool to extract cabinet files The program was able to overwrite files in upper directories This could lead an attacker to overwrite arbitrary files For the stable distribution (woody) this problem has been fixed in version 02-2b For the unstable distribution (sid) this problem has b ...