CERTA-2003-AVI-138
Vulnerability from certfr_avis
None
Description
Lors de l'extraction des fichiers contenus dans une archive au format .zip, le chemin des fichiers n'est pas correctement validé.
Il est alors possible, pour un utilisateur mal intentionné, de constituer une archive contenant des fichiers qui seront extraits dans un répertoire parent du répertoire d'extraction initial (présence de la séquence "../" dans le chemin d'accès).
Solution
Appliquer le correctif de l'éditeur :
-
Bulletin de sécurité DSA-344 de Debian :
http://www.debian.org/security/2003/dsa-344 -
Bulletin de sécurité MDKSA-2003:073 de Mandrake :
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:073 -
Bulletin de sécurité RHSA-2003:199 de Red Hat :
http://rhn.redhat.com/errata/RHSA-2003-199.html
Tous les systèmes possédant la version 5.50 (ou antérieure) de UnZip.
Impacted products
| Vendor | Product | Description |
|---|
References
| Title | Publication Time | Tags | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [],
"affected_systems_content": "\u003cp\u003eTous les syst\u00e8mes poss\u00e9dant la version 5.50 (ou ant\u00e9rieure) de UnZip.\u003c/p\u003e",
"content": "## Description\n\nLors de l\u0027extraction des fichiers contenus dans une archive au format\n.zip, le chemin des fichiers n\u0027est pas correctement valid\u00e9.\n\nIl est alors possible, pour un utilisateur mal intentionn\u00e9, de\nconstituer une archive contenant des fichiers qui seront extraits dans\nun r\u00e9pertoire parent du r\u00e9pertoire d\u0027extraction initial (pr\u00e9sence de la\ns\u00e9quence \"../\" dans le chemin d\u0027acc\u00e8s).\n\n## Solution\n\nAppliquer le correctif de l\u0027\u00e9diteur :\n\n- Bulletin de s\u00e9curit\u00e9 DSA-344 de Debian :\n\n http://www.debian.org/security/2003/dsa-344\n\n- Bulletin de s\u00e9curit\u00e9 MDKSA-2003:073 de Mandrake :\n\n http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:073\n\n- Bulletin de s\u00e9curit\u00e9 RHSA-2003:199 de Red Hat :\n\n http://rhn.redhat.com/errata/RHSA-2003-199.html\n",
"cves": [],
"initial_release_date": "2003-08-20T00:00:00",
"last_revision_date": "2003-08-20T00:00:00",
"links": [
{
"title": "Site Info-Zip :",
"url": "http://www.info-zip.org/pub/infozip/UnZip.html"
}
],
"reference": "CERTA-2003-AVI-138",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2003-08-20T00:00:00.000000"
}
],
"risks": [
{
"description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 du syst\u00e8me"
}
],
"summary": null,
"title": "Vuln\u00e9rabilit\u00e9 de la commande UnZip",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 MDKSA-2003:071 de Mandrake",
"url": null
},
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 RHSA-2003:199 de RedHat",
"url": null
},
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 DSA-344 de Debian",
"url": null
}
]
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…