CVE-2003-0282
published 2003-06-16CVE-2003-0282: Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are…
PriorityP433low2.6CVSS 2.0
AVNACHAuNCNIPAN
EXPLOIT
EPSS
22.53%
97.4th percentile
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | unzip | < unzip 5.50-3 (bookworm) | unzip 5.50-3 (bookworm) |
| info-zip | unzip | — | — |
| sco | openlinux_server | — | — |
| sco | openlinux_workstation | — | — |
| unzip_project | unzip | >= 0 < 5.50-3 | 5.50-3 |
| unzip_project | unzip | >= 0 < 5.50-3 | 5.50-3 |
| unzip_project | unzip | >= 0 < 5.50-3 | 5.50-3 |
| unzip_project | unzip | >= 0 < 5.50-3 | 5.50-3 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2003-05-09·CVSS 2.6
CVE-2003-0282 [LOW] security flaw
security flaw
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
Debian
CVE-2003-0282: unzip - Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite ar...
vendor_debian·2003·CVSS 2.6
CVE-2003-0282 [LOW] CVE-2003-0282: unzip - Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite ar...
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
Scope: local
bookworm: resolved (fixed in 5.50-3)
bullseye: resolved (fixed in 5.50-3)
forky: resolved (fixed in 5.50-3)
sid: resolved (fixed in 5.50-3)
trixie: resolved (fixed in 5.50-3)
GHSA
GHSA-8g9q-xjgw-r992: Directory traversal vulnerability in UnZip 5
ghsa_unreviewed·2022-05-03
CVE-2003-0282 [LOW] GHSA-8g9q-xjgw-r992: Directory traversal vulnerability in UnZip 5
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
OSV
CVE-2003-0282: Directory traversal vulnerability in UnZip 5
osv·2003-06-16·CVSS 2.6
CVE-2003-0282 [LOW] CVE-2003-0282: Directory traversal vulnerability in UnZip 5
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
No detection rules found.
CWE
Incorrect Behavior Order: Validate Before Filter
mitre_cwe·CVSS 6.4
[MEDIUM] CWE-181 Incorrect Behavior Order: Validate Before Filter
CWE-181: Incorrect Behavior Order: Validate Before Filter
The product validates data before it has been filtered, which prevents the product from detecting data that becomes invalid after the filtering step.
This can be used by an attacker to bypass the validation and launch attacks that expose weaknesses that would otherwise be prevented, such as injection.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Access Control. Impact: Bypass Protection Mechanism.
Potential Mitigations:
[Implementation] Inputs should be decoded and canonicalized to the application's current internal representation before being filtered.
Examples:
This script creates a subdirectory within a user directory and sets the user as the owner.
While the script attempts to screen for '..' se
CWE
Incorrect Behavior Order: Early Validation
mitre_cwe
CWE-179 Incorrect Behavior Order: Early Validation
CWE-179: Incorrect Behavior Order: Early Validation
The product validates input before applying protection mechanisms that modify the input, which could allow an attacker to bypass the validation via dangerous inputs that only arise after the modification.
Product needs to validate data at the proper time, after data has been canonicalized and cleansed. Early validation is susceptible to various manipulations that result in dangerous inputs that are produced by canonicalization and cleansing.
Modes of Introduction:
Phase: Implementation
Note: Since early validation errors usually arise from improperly implemented defensive mechanisms, it is likely that these will be introduced more frequently as secure programming becomes implemented more widely.
Common Consequences:
Scope: Access Cont
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txtftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000672http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-017-01http://marc.info/?l=bugtraq&m=105259038503175&w=2http://marc.info/?l=bugtraq&m=105786446329347&w=2http://www.ciac.org/ciac/bulletins/n-111.shtmlhttp://www.debian.org/security/2003/dsa-344http://www.info-zip.org/FAQ.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2003:073http://www.redhat.com/support/errata/RHSA-2003-199.htmlhttp://www.redhat.com/support/errata/RHSA-2003-200.htmlhttp://www.securityfocus.com/bid/7550http://www.turbolinux.com/security/TLSA-2003-42.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/12004https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A619ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txtftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000672http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-017-01http://marc.info/?l=bugtraq&m=105259038503175&w=2http://marc.info/?l=bugtraq&m=105786446329347&w=2http://www.ciac.org/ciac/bulletins/n-111.shtmlhttp://www.debian.org/security/2003/dsa-344http://www.info-zip.org/FAQ.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2003:073http://www.redhat.com/support/errata/RHSA-2003-199.htmlhttp://www.redhat.com/support/errata/RHSA-2003-200.htmlhttp://www.securityfocus.com/bid/7550http://www.turbolinux.com/security/TLSA-2003-42.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/12004https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A619
2003-06-16
Published