Info-ZIP UnZip 5.50 - Encoded Character Hostile Destination Path
Author: Jelmer
type: remote
platform: linux
port:
date_added: 2003-05-10
date_updated: 2012-11-12
verified: 1
codes: CVE-2003-0282;OSVDB-2168
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/7550/info
Info-ZIP UnZip contains a vulnerability during the handling of pathnames for archived files. Specifically, when certain encoded characters are inserted into '../' directory traversal sequences, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem - including paths containing system binaries and other sensitive or confidential information.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/22584.zip