cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-11-29T20:55:44

Updated: 2024-08-06T05:02:43.388Z

Reserved: 2015-02-23T00:00:00

Link: CVE-2015-2060

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-11-29T21:15:10.887

Modified: 2021-04-26T11:45:21.097

Link: CVE-2015-2060

cve-icon Redhat

No data.