cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-11-29T20:55:44

Updated: 2019-11-29T20:55:44

Reserved: 2015-02-23T00:00:00


Link: CVE-2015-2060

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-11-29T21:15:10.887

Modified: 2021-04-26T11:45:21.097


Link: CVE-2015-2060

JSON object: View

cve-icon Redhat Information

No data.

CWE