← All CVEs

CVE-2018-10860

medium · 5.4

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.

5.4
CVSS
48.7%
EPSS (exploit prob.)
99th
EPSS percentile
2018-06-29
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux17.10
canonicalubuntu_linux18.04
debiandebian_linux8.0
perl-archive-zip_projectperl-archive-zipall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-10860