MGASA-2019-0005
Dashboard / Vulnerabilities / MGASA-2019-0005
Summary: Updated plexus-archiver packages fix security vulnerability
Details: A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names. A remote attacker could use this vulnerability to write files outside the target directory and overwrite existing files with malicious code or vulnerable configurations (CVE-2018-1002200).
References: https://advisories.mageia.org/MGASA-2019-0005.html, https://bugs.mageia.org/show_bug.cgi?id=23174, https://lists.fedoraproject.org/archives/list/[email protected]/thread/I7XAAUCTHL2PDJHW5Q2IYATOAXX4AFFU/
Affected packages
Package
Name: plexus-archiver
Purl: pkg:rpm/mageia/plexus-archiver?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
