CVE-2007-2058: Medium severity PicoZip PicoZip vulnerability
Published Apr 18, 2007
·Updated
Directory traversal vulnerability in Acubix PicoZip 4.02 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the file path in an (1) GZ, (2) TAR, (3) RAR, (4) JAR, or (5) ZIP archive.
Affected Software
1 affected component
PicoZip PicoZip=4.02
Event History
Apr 18, 2007
CVE Published
03:19 AM
CVE Published
via MITRE·06:20 AM
Data Sourced
via MITRE·06:20 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2058?
The CVE-2007-2058 vulnerability is considered to have a moderate severity due to the potential for file overwriting.
2
How do I fix CVE-2007-2058?
To fix CVE-2007-2058, upgrade to a version of PicoZip that is not vulnerable to directory traversal attacks.
3
What types of files are affected by CVE-2007-2058?
CVE-2007-2058 affects GZ, TAR, RAR, JAR, and ZIP file formats.
4
Who is affected by CVE-2007-2058?
Users of Acubix PicoZip version 4.02 are affected by CVE-2007-2058.
5
What can attackers do with CVE-2007-2058?
Attackers can exploit CVE-2007-2058 to overwrite arbitrary files on the user's system.