Security Advisory

CVE-2005-3123

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2005-10-30 20:00:00
Last updated 2024-08-07 23:01:57
Assigner debian
State PUBLISHED

Description

Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed.