unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with ".." (dot dot) sequences in a filename.
References
Configurations
History
No history.
Information
Published : 2006-03-13 19:34
Updated : 2024-02-04 16:52
NVD link : CVE-2006-0950
Mitre link : CVE-2006-0950
CVE.ORG link : CVE-2006-0950
JSON object : View
Products Affected
unalz
- unalz
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')