CVE-2018-17828
published 2018-10-01CVE-2018-17828: Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function…
PriorityP428medium5.5CVSS 3.0
AVLACLPRNUIRSUCNIHAN
EPSS
1.54%
72.1th percentile
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zziplib | — | — |
| gdraheim | zziplib | — | — |
| msrc | cbl2_zziplib_0.13.69-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
vendor_msrc·2018-10-09·CVSS 5.5
CVE-2018-17828 [MEDIUM] CWE-22 Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the
Red Hat
zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c
vendor_redhat·2018-09-25·CVSS 5.5
CVE-2018-17828 [MEDIUM] CWE-22 zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c
zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
It was discovered that zziplib is vulnerable to a directory traversal flaw in most of its unzip binaries, including unzip-mem, unzzipcat-mem, unzzipcat-big, unzzipcat-mix, and unzzipcat-zip. An attacker may use this flaw to write files outside the intended target directory, overwriting existing files, or creating new ones.
Debian
CVE-2018-17828: zziplib - Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwri...
vendor_debian·2018·CVSS 5.5
CVE-2018-17828 [MEDIUM] CVE-2018-17828: zziplib - Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwri...
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-g8rp-fvg9-52vv: Directory traversal vulnerability in ZZIPlib 0
ghsa_unreviewed·2022-05-14
CVE-2018-17828 [MEDIUM] CWE-22 GHSA-g8rp-fvg9-52vv: Directory traversal vulnerability in ZZIPlib 0
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
OSV
CVE-2018-17828: Directory traversal vulnerability in ZZIPlib 0
osv·2018-10-01·CVSS 5.5
CVE-2018-17828 [MEDIUM] CVE-2018-17828: Directory traversal vulnerability in ZZIPlib 0
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-17828 zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c [fedora-all]
bugzilla·2018-10-03·CVSS 5.5
CVE-2018-17828 [MEDIUM] CVE-2018-17828 zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c [fedora-all]
CVE-2018-17828 zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2018-17828 zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c
bugzilla·2018-10-03·CVSS 5.5
CVE-2018-17828 [MEDIUM] CVE-2018-17828 zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c
CVE-2018-17828 zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c
A flaw was found in ZZIPlib 0.13.69. A directory traversal vulnerability allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
References:
https://github.com/gdraheim/zziplib/issues/62
Discussion:
Created zziplib tracking bugs for this issue:
Affects: fedora-all [bug 1635889]
---
Upstream patch:
https://github.com/gdraheim/zziplib/commit/f609ae8971f3c0ce64d38276b778001d0bbfc84b
---
The same flaw is present in unzzipcat-big.c, unzzipcat-mix.c and unzzipcat-zip.c.
---
The same problem is also present in unzip-mem.c.
Proposed patch for unzip-mem.c:
https://github.com/gdraheim/zziplib/files/2482517/patc
2018-10-01
Published