PKWare PKZip敌对目标路径漏洞

漏洞信息详情

PKWare PKZip敌对目标路径漏洞

漏洞简介

PKZip (pkzipc) 4.00及其早期的控制台版本存在目录遍历漏洞。远程攻击者可以在提取存档期间借助在存档文件上的..(点 点)攻击覆盖具有-rec(递归)选项的任意文件。

漏洞公告

Users should contact the vendor to determine if a fixed version is available for their operating system.
FreeBSD has released upgrades. Users are advised to upgrade their Ports
collection and reinstall the affected port.

参考网址

来源: BUGTRAQ
名称: 20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers
链接:http://online.securityfocus.com/archive/1/196445

来源: www.security.nnov.ru
链接:http://www.security.nnov.ru/advisories/archdt.asp

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享