Candidate: CVE-2016-4313 PublicDate: 2017-04-24 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4313 https://www.exploit-db.com/exploits/39816/ Description: Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_extplorer: upstream_extplorer: needs-triage precise_extplorer: ignored (reached end-of-life) precise/esm_extplorer: DNE (precise was needed) trusty_extplorer: released (2.1.0b6+dfsg.3-4+deb7u4build0.14.04.1) trusty/esm_extplorer: DNE (trusty was released [2.1.0b6+dfsg.3-4+deb7u4build0.14.04.1]) vivid/stable-phone-overlay_extplorer: DNE vivid/ubuntu-core_extplorer: DNE wily_extplorer: ignored (reached end-of-life) xenial_extplorer: released (2.1.0b6+dfsg.3-4+deb7u4ubuntu0.16.04.1) yakkety_extplorer: DNE zesty_extplorer: DNE devel_extplorer: DNE