CVE-2018-1000544
published 2018-06-26CVE-2018-1000544: rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.50%
90.4th percentile
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-zip | < ruby-zip 1.2.2-1 (bookworm) | ruby-zip 1.2.2-1 (bookworm) |
| redhat | cloudforms | — | — |
| rubyzip_project | rubyzip | <= 1.2.1 | — |
| rubyzip_project | rubyzip | >= 0 < 1.2.2 | 1.2.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
osv·2018-09-06·CVSS 9.8
CVE-2018-1000544 [CRITICAL] Rubyzip gem contains a Directory Traversal vulnerability in zip file component
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete.
GHSA
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
ghsa·2018-09-06·CVSS 9.8
CVE-2018-1000544 [CRITICAL] CWE-434 Rubyzip gem contains a Directory Traversal vulnerability in zip file component
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete.
OSV
CVE-2018-1000544: rubyzip gem rubyzip version 1
osv·2018-06-26·CVSS 9.8
CVE-2018-1000544 [CRITICAL] CVE-2018-1000544: rubyzip gem rubyzip version 1
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
Red Hat
rubyzip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file
vendor_redhat·2018-06-05·CVSS 9.8
CVE-2018-1000544 [CRITICAL] CWE-20 rubyzip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file
rubyzip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
A directory and symbolic link traversal flaw was found in the way rubyzip gem extracts zip files. An attacker, with access to a privileged application capable of extracting zip files, could use this flaw to write new files to arbitrary paths, accessible by the aforementioned privileged
Debian
CVE-2018-1000544: ruby-zip - rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vul...
vendor_debian·2018·CVSS 9.8
CVE-2018-1000544 [CRITICAL] CVE-2018-1000544: ruby-zip - rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vul...
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
Scope: local
bookworm: resolved (fixed in 1.2.2-1)
bullseye: resolved (fixed in 1.2.2-1)
forky: resolved (fixed in 1.2.2-1)
sid: resolved (fixed in 1.2.2-1)
trixie: resolved (fixed in 1.2.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000544 rubyzip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file
bugzilla·2018-06-19·CVSS 9.8
CVE-2018-1000544 [CRITICAL] CVE-2018-1000544 rubyzip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file
CVE-2018-1000544 rubyzip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file
A vulnerability has been found in the way developers have implemented the archive extraction of files. An arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar,xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder. Of course if an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily. This affects multiple libraries that lacks of a high level APIs tha
Bugzilla
CVE-2018-1000544 rubygem-rubyzip: various flaws [fedora-all]
bugzilla·2018-06-19·CVSS 9.8
CVE-2018-1000544 [CRITICAL] CVE-2018-1000544 rubygem-rubyzip: various flaws [fedora-all]
CVE-2018-1000544 rubygem-rubyzip: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
https://access.redhat.com/errata/RHSA-2018:3466https://github.com/rubyzip/rubyzip/issues/369https://lists.debian.org/debian-lts-announce/2018/08/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00002.htmlhttps://access.redhat.com/errata/RHSA-2018:3466https://github.com/rubyzip/rubyzip/issues/369https://lists.debian.org/debian-lts-announce/2018/08/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00002.html
2018-06-26
Published