FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

unzoo -- Directory Traversal Vulnerability

Affected packages
unzoo < 4.4_1


VuXML ID 5a945904-73b1-11db-91d2-0002a5c2f4ef
Discovery 2004-10-18
Entry 2006-11-14
Modified 2006-12-15

Secunia reports:

Doubles has discovered a vulnerability in Unzoo, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an input validation error when unpacking archives. This can be exploited via a directory traversal attack to overwrite files outside the directory, where the files are extracted to, if a user is tricked into extracting a malicious archive using Unzoo.


Bugtraq ID 11417