The tar utility does not properly filter file names containing
"../", meaning that a hostile archive can, if unpacked by an
unsuspecting user, overwrite any file that is writable by that user. GNU
tar versions 1.13.19 and earlier are vulnerable; unzip through version 5.42
has the same vulnerability.
Posted Oct 2, 2002 21:45 UTC (Wed) by roelofs (subscriber, #2599)
[Link]
The UnZip vulnerability was reported on Bugtraq more than a year ago and has been prominently displayed
on the UnZip home page
ever since then. UnZip 5.5, which fixes the bug, was released more than seven
and a half months ago.
There are also a number of related (i.e., data-loss) bugs against various versions
of Zip and UnZip listed on the Info-ZIP FAQ page.