Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2005-02-28 21:00
Updated : 2017-07-10 18:30
NVD link : CVE-2004-1027
Mitre link : CVE-2004-1027
JSON object : View
CWE
Products Affected
arj_software_inc.
- unarj
gentoo
- linux