cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-11-29T20:55:44
Updated: 2024-08-06T05:02:43.388Z
Reserved: 2015-02-23T00:00:00
Link: CVE-2015-2060
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2019-11-29T21:15:10.887
Modified: 2021-04-26T11:45:21.097
Link: CVE-2015-2060
Redhat
No data.