Back to search
CVE-2006-0950
Published: Mar 13, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with ".." (dot dot) sequences in a filename.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2006-0938
vdb-entry
x_refsource_VUPEN
20060313 Secunia Research: unalz Filename Handling
mailing-list
x_refsource_FULLDISC
17105
vdb-entry
x_refsource_BID
23835
vdb-entry
x_refsource_OSVDB
19063
third-party-advisory
x_refsource_SECUNIA
575
third-party-advisory
x_refsource_SREASON
1015780
vdb-entry
x_refsource_SECTRACK
unalz-archive-directory-traversal(25171)
vdb-entry
x_refsource_XF
http://secunia.com/secunia_research/2006-16/
x_refsource_MISC
20060313 Secunia Research: unalz Filename Handling Directory TraversalVulnerability
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now