CVE-2018-1000544
26.06.2018, 16:29
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
Vendor | Product | Version |
---|---|---|
rubyzip_project | rubyzip | 𝑥 ≤ 1.2.1 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
redhat | cloudforms | 4.6 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ruby-zip |
|
References