First published: Tue Feb 28 2006(Updated: )
Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Smithmicro Stuffit Deluxe | =9.0 | |
Smithmicro Stuffit Standard | =9.0 | |
Smithmicro Stuffit Expander | =9.0.0.21_engine_9.0.0.21 | |
Smithmicro Zipmagic Deluxe | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0926 is considered a high-severity vulnerability due to its potential to allow remote attackers to overwrite arbitrary files.
To mitigate CVE-2006-0926, users should update Allume StuffIt Standard, Deluxe, ZipMagic Deluxe, and StuffIt Expander to the latest versions provided by Smith Micro.
CVE-2006-0926 affects Allume StuffIt Standard 9.0, StuffIt Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21.
A directory traversal vulnerability allows an attacker to access restricted directories and manipulate files outside of the intended directory.
Yes, CVE-2006-0926 can be exploited remotely by attackers using crafted pathnames in zip or tar archives.