CVE-2004-0916Path Traversal in Project Cabextract

5 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
1.9%
top 16.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateApr 29

Description

Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDcabextract_project/cabextract0.2, 0.6, 1.0+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3c6r-mr2w-qgv5: Directory traversal vulnerability in cabextract before 12022-04-29
OSV
CVE-2004-0916: Directory traversal vulnerability in cabextract before 12005-01-27
CVEList
CVE-2004-0916: Directory traversal vulnerability in cabextract before 12004-11-19

📋Vendor Advisories

1
Debian
CVE-2004-0916: cabextract - Directory traversal vulnerability in cabextract before 1.1 allows remote attacke...2004
CVE-2004-0916 — Path Traversal in Project Cabextract | cvebase