First published: Tue Feb 28 2006(Updated: )
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pear Archive Zip | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0932 is considered a critical vulnerability due to its ability to allow remote attackers to create and overwrite arbitrary files.
To mitigate CVE-2006-0932, upgrade to the latest version of PEAR::Archive_Zip that addresses this vulnerability.
CVE-2006-0932 can be exploited through crafted ZIP archive pathnames, leading to unauthorized file creation and manipulation.
CVE-2006-0932 affects PEAR::Archive_Zip version 1.1 and possibly earlier versions.
Yes, CVE-2006-0932 specifically affects PHP applications utilizing the PEAR::Archive_Zip library.