Candidate: CVE-2018-1002209 PublicDate: 2018-07-25 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1002209 https://bugzilla.redhat.com/show_bug.cgi?id=1593011 Description: QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N [5.5 MEDIUM] Patches_libquazip: upstream_libquazip: released (0.7.6-1) precise/esm_libquazip: DNE trusty_libquazip: ignored (reached end-of-life) trusty/esm_libquazip: DNE (trusty was needed) xenial_libquazip: ignored (end of standard support, was needed) artful_libquazip: ignored (reached end-of-life) bionic_libquazip: needed cosmic_libquazip: not-affected (0.7.6-1) disco_libquazip: not-affected (0.7.6-1) eoan_libquazip: not-affected (0.7.6-1) focal_libquazip: not-affected (0.7.6-1) groovy_libquazip: not-affected (0.7.6-1) hirsute_libquazip: not-affected (0.7.6-1) impish_libquazip: not-affected (0.7.6-1) jammy_libquazip: not-affected (0.7.6-1) devel_libquazip: not-affected (0.7.6-1)