CVE-2018-1000544
26.06.2018, 16:29
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
| Vendor | Product | Version |
|---|---|---|
| rubyzip_project | rubyzip | 𝑥 ≤ 1.2.1 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| redhat | cloudforms | 4.6 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ruby-zip |
|
References