First published: Thu Jul 12 2001(Updated: )
Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Info-ZIP UnZip | <=5.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1268 is classified as a high severity vulnerability due to the potential for file overwriting.
To fix CVE-2001-1268, upgrade to Info-ZIP UnZip version 5.43 or later.
CVE-2001-1268 is a directory traversal vulnerability that allows arbitrary file overwriting.
CVE-2001-1268 affects Info-ZIP UnZip versions 5.42 and earlier.
Yes, CVE-2001-1268 can potentially be exploited remotely during the archive extraction process.