Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-1002200
Description:plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
Test IDs: 1.3.6.1.4.1.25623.1.0.882911   1.3.6.1.4.1.25623.1.0.874677   1.3.6.1.4.1.25623.1.0.704227   1.3.6.1.4.1.25623.1.1.10.2019.0005   1.3.6.1.4.1.25623.1.1.12.2021.4832.1   1.3.6.1.4.1.25623.1.0.874676  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-1002200
Debian Security Information: DSA-4227 (Google Search)
https://www.debian.org/security/2018/dsa-4227
https://github.com/snyk/zip-slip-vulnerability
https://snyk.io/research/zip-slip-vulnerability
https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31680
RedHat Security Advisories: RHSA-2018:1836
https://access.redhat.com/errata/RHSA-2018:1836
RedHat Security Advisories: RHSA-2018:1837
https://access.redhat.com/errata/RHSA-2018:1837




© 1998-2025 E-Soft Inc. All rights reserved.