Security Advisory

CVE-2018-10860

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-06-29 19:00:00
Last updated 2024-08-05 07:46:47
Assigner redhat
CVSS score 5.4
State PUBLISHED

Description

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.