CVE-2018-17828

Name
CVE-2018-17828
Description
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/gdraheim/zziplib/issues/62

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zziplib_project:zziplib:0.13.69:*:*:*:*:*:*:* zziplib == None == 0.13.69

Vulnerable and fixed packages

Source package Branch Version Maintainer Status