SB2018092202 - Debian update for libarchive-zip-perl
Published: September 22, 2018 Updated: March 18, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Path traversal (CVE-ID: CVE-2018-10860)
The vulnerability allows a remote attacker to conduct directory traversal attack on the target system.
The vulnerability exists in the Archive::Zip module due to improper sanitization of paths while extracting zip files. A remote unauthenticated attacker can provide a specially crafted archive for processing, bypass security restrictions and write or overwrite arbitrary files in the context of the perl interpreter.
Remediation
Install update from vendor's website.