Severity
9.8CRITICAL
EPSS
0.4%
top 36.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateSep 6

Description

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

RubyGemsrubyzip< 1.2.2
Debianruby-zip< 1.2.2-1+3

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

4
OSV
Rubyzip gem contains a Directory Traversal vulnerability in zip file component2018-09-06
GHSA
Rubyzip gem contains a Directory Traversal vulnerability in zip file component2018-09-06
OSV
CVE-2018-1000544: rubyzip gem rubyzip version 12018-06-26
CVEList
CVE-2018-1000544: rubyzip gem rubyzip version 12018-06-26

📋Vendor Advisories

2
Red Hat
rubyzip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file2018-06-05
Debian
CVE-2018-1000544: ruby-zip - rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vul...2018

💬Community

2
Bugzilla
CVE-2018-1000544 rubyzip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file2018-06-19
Bugzilla
CVE-2018-1000544 rubygem-rubyzip: various flaws [fedora-all]2018-06-19
CVE-2018-1000544 (CRITICAL CVSS 9.8) | rubyzip gem rubyzip version 1.2.1 a | cvebase.io