Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 6: MGASA-2019-0005 Critical: Plexus-Archiver Path Traversal

mageia
Calendar Grey January 5, 2019
Dist Mageia Esm H88
MGASA-2019-0005 - Updated plexus-archiver packages fix security vulnerability Publication date: 05 J
A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names

Summary

A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names. A remote attacker could use this vulnerability to write files outside the target directory and overwrite existing files with malicious code or vulnerable configurations (CVE-2018-1002200).

References

- https://bugs.mageia.org/show_bug.cgi?id=23174

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/I7XAAUCTHL2PDJHW5Q2IYATOAXX4AFFU/

- https://www.cve.org/CVERecord?id=CVE-2018-1002200

Resolution

SRPMS

- 6/core/plexus-archiver-3.4-1.1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0005.html
Type: security
CVE: CVE-2018-1002200

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here