Description
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
Published: 2018-06-29
Score: 5.4 Medium
EPSS: 5.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-1440-1 libarchive-zip-perl security update
Debian DSA Debian DSA DSA-4300-1 libarchive-zip-perl security update
EUVD EUVD EUVD-2018-2927 perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
Ubuntu USN Ubuntu USN USN-3703-1 Archive Zip
Ubuntu USN Ubuntu USN USN-3703-2 Archive Zip vulnerability
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.06484}

epss

{'score': 0.00794}


Subscriptions

Canonical Ubuntu Linux
Debian Debian Linux
Perl-archive-zip Project Perl-archive-zip
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T07:46:47.302Z

Reserved: 2018-05-09T00:00:00.000Z

Link: CVE-2018-10860

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-29T19:29:00.237

Modified: 2024-11-21T03:42:09.747

Link: CVE-2018-10860

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-06-28T00:00:00Z

Links: CVE-2018-10860 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses