Debian Libarchive-Zip-Perl vulnerabilities
2 known vulnerabilities affecting debian/libarchive-zip-perl.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2018-10860MEDIUMCVSS 5.4fixed in libarchive-zip-perl 1.62-1 (bookworm)2018
CVE-2018-10860 [MEDIUM] CVE-2018-10860: libarchive-zip-perl - perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was ...
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
Scope: loc
debian
CVE-2004-1096HIGHCVSS 7.5PoCfixed in libarchive-zip-perl 1.14-1 (bookworm)2004
CVE-2004-1096 [HIGH] CVE-2004-1096: libarchive-zip-perl - Archive::Zip Perl module before 1.14, when used by antivirus programs such as am...
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
Scope: local
bookworm: resolved (fixed in 1.14-1)
bullseye: r
debian