Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2005-03-01 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-1027
Mitre link : CVE-2004-1027
CVE.ORG link : CVE-2004-1027
JSON object : View
Products Affected
arjsoftware
- unarj
debian
- debian_linux
gentoo
- linux
CWE