CVE-2006-0932: Medium severity PEAR Pear Archive Zip vulnerability
Published Feb 28, 2006
·Updated
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::ArchiveZip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.
Affected Software
1 affected component
PEAR Pear Archive Zip=1.1
Event History
Feb 28, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0932?
CVE-2006-0932 is considered a critical vulnerability due to its ability to allow remote attackers to create and overwrite arbitrary files.
2
How do I fix CVE-2006-0932?
To mitigate CVE-2006-0932, upgrade to the latest version of PEAR::Archive_Zip that addresses this vulnerability.
3
What type of attacks can exploit CVE-2006-0932?
CVE-2006-0932 can be exploited through crafted ZIP archive pathnames, leading to unauthorized file creation and manipulation.
4
Which versions of PEAR::Archive_Zip are affected by CVE-2006-0932?
CVE-2006-0932 affects PEAR::Archive_Zip version 1.1 and possibly earlier versions.
5
Is CVE-2006-0932 specific to a particular programming language?
Yes, CVE-2006-0932 specifically affects PHP applications utilizing the PEAR::Archive_Zip library.