WinZip Tar Hostile Destination Path...

- AV AC AU C I A
发布: 2002-12-17
修订: 2025-04-13

WinZip is prone to a security vulnerability when unpacking .tar archives. The problem is in the handling of pathnames. By specifying a path for an archived item which points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem. An attacker may take advantage of this vulnerability to cause malicious files to be placed anywhere on a target filesystem. This issue is present when the "Extract folder names" option is checked in the extraction dialogue, which is the default setting and is used to retain the directory structure when extracting files.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息