CVE-2018-17828 (NVD)

2018-10-01

Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.

Products Zziplib
Type Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
First patch - None (likely due to unavailable code)
Links https://github.com/gdraheim/zziplib/issues/62