Dzip Remote Directory Traversal Vulnerability
BID:13867
Info
Dzip Remote Directory Traversal Vulnerability
| Bugtraq ID: | 13867 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2005 12:00AM |
| Updated: | Jun 06 2005 12:00AM |
| Credit: | Gentoo reported this issue. |
| Vulnerable: |
Gentoo Linux Dzip Dzip 2.84 Dzip Dzip 2.83 Dzip Dzip 2.82 Dzip Dzip 2.81 Dzip Dzip 2.9 Dzip Dzip 2.8 |
| Not Vulnerable: | |
Discussion
Dzip Remote Directory Traversal Vulnerability
Dzip is affected by a directory traversal vulnerability.
A successful attack can allow the attacker to place potentially malicious files in arbitrary locations.
This attack would occur with the privileges of the application.
Dzip 2.9 and prior versions are reportedly vulnerable.
Dzip is affected by a directory traversal vulnerability.
A successful attack can allow the attacker to place potentially malicious files in arbitrary locations.
This attack would occur with the privileges of the application.
Dzip 2.9 and prior versions are reportedly vulnerable.
Exploit / POC
Dzip Remote Directory Traversal Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Dzip Remote Directory Traversal Vulnerability
Solution:
Gentoo has released advisory GLSA 200506-03 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=games-utils/dzip-2.9-r1"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo has released advisory GLSA 200506-03 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=games-utils/dzip-2.9-r1"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.