First published: Wed Apr 18 2007(Updated: )
Directory traversal vulnerability in Acubix PicoZip 4.02 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the file path in an (1) GZ, (2) TAR, (3) RAR, (4) JAR, or (5) ZIP archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PicoZip | =4.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2007-2058 vulnerability is considered to have a moderate severity due to the potential for file overwriting.
To fix CVE-2007-2058, upgrade to a version of PicoZip that is not vulnerable to directory traversal attacks.
CVE-2007-2058 affects GZ, TAR, RAR, JAR, and ZIP file formats.
Users of Acubix PicoZip version 4.02 are affected by CVE-2007-2058.
Attackers can exploit CVE-2007-2058 to overwrite arbitrary files on the user's system.