Vulnerability Name: | CVE-2004-1027 (CCN-17684) | ||||||||
Assigned: | 2004-10-11 | ||||||||
Published: | 2004-10-11 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Sun Oct 10 2004 - 17:43:10 CDT unarj dir-transversal bug (../../../..) Source: MITRE Type: CNA CVE-2004-1027 Source: CCN Type: Linux Software Directory Unarj - Decompressor for .arj format archives Source: FULLDISC Type: UNKNOWN 20041010 unarj dir-transversal bug (../../../..) Source: FEDORA Type: UNKNOWN FLSA:2272 Source: CCN Type: RHSA-2005-007 unarj security update Source: GENTOO Type: UNKNOWN GLSA-200411-29 Source: DEBIAN Type: UNKNOWN DSA-628 Source: DEBIAN Type: UNKNOWN DSA-652 Source: DEBIAN Type: DSA-652 unarj -- several vulnerabilities Source: CCN Type: GLSA-200411-29 unarj: Long filenames buffer overflow and a path traversal vulnerability Source: REDHAT Type: UNKNOWN RHSA-2005:007 Source: BID Type: Patch, Vendor Advisory 11436 Source: CCN Type: BID-11436 ARJ Software UNARJ Remote Directory Traversal Vulnerability Source: XF Type: UNKNOWN unarj-directory-traversal(17684) Source: XF Type: UNKNOWN unarj-directory-traversal(17684) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |