[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-1000544 -- ruby-zip

ID: oval:org.secpod.oval:def:2001572Date: (C)2019-04-21   (M)2021-06-02
Class: VULNERABILITYFamily: unix




rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..

Platform:
Debian 8.x
Debian 9.x
Product:
ruby-zip
Reference:
CVE-2018-1000544
CVE    1
CVE-2018-1000544
CPE    4
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:github:ruby_zip
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies