FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

unzoo -- Directory Traversal Vulnerability

Affected packages
unzoo < 4.4_1

Details

VuXML ID 5a945904-73b1-11db-91d2-0002a5c2f4ef
Discovery 2004-10-18
Entry 2006-11-14
Modified 2006-12-15

Secunia reports:

Doubles has discovered a vulnerability in Unzoo, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an input validation error when unpacking archives. This can be exploited via a directory traversal attack to overwrite files outside the directory, where the files are extracted to, if a user is tricked into extracting a malicious archive using Unzoo.

References

Bugtraq ID 11417
URL http://secunia.com/advisories/12857/
URL http://securitytracker.com/alerts/2004/Oct/1011673.html