LWN.net Logo

cabextract: missing directory sanitizing

Package(s):cabextract CVE #(s):CAN-2004-0916
Created:October 28, 2004 Updated:November 2, 2004
Description: The cabinet file extraction tool cabextract may allow arbitrary files in upper directories to be overwritten.
Alerts:
Debian DSA-574-1 2004-10-28

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.