5

CVE-2004-1027

Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.

Data is provided by the National Vulnerability Database (NVD)
ArjsoftwareUnarj Version2.62
ArjsoftwareUnarj Version2.63 Updatea
ArjsoftwareUnarj Version2.64
ArjsoftwareUnarj Version2.65
DebianDebian Linux Version3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.28% 0.9
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N