Path traversal in DFArc - CVE-2018-0496
Published: July 3, 2018 / Updated: July 4, 2018
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to path traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version). A remote unauthenticated attacker can conduct directory traversal attack, bypass security restrictions and overwrite arbitrary files on the user's system.
Affected software
Fedora
freedink-dfarc
How to mitigate CVE-2018-0496
freedink-dfarc - update to 3.14-1.fc28