CVE-2001-1268: Low severity Info-ZIP UnZip vulnerability
Published Jul 12, 2001
·Updated
Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.
Affected Software
1 affected component
Info-ZIP UnZip<=5.42
Remediation
Patch Available
Event History
Jul 12, 2001
CVE Published
04:00 AM
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1268?
CVE-2001-1268 is classified as a high severity vulnerability due to the potential for file overwriting.
2
How do I fix CVE-2001-1268?
To fix CVE-2001-1268, upgrade to Info-ZIP UnZip version 5.43 or later.
3
What type of vulnerability is CVE-2001-1268?
CVE-2001-1268 is a directory traversal vulnerability that allows arbitrary file overwriting.
4
Which versions of Info-ZIP UnZip are affected by CVE-2001-1268?
CVE-2001-1268 affects Info-ZIP UnZip versions 5.42 and earlier.
5
Can CVE-2001-1268 be exploited remotely?
Yes, CVE-2001-1268 can potentially be exploited remotely during the archive extraction process.