Vulnerability Description
Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| John G. Myers | Mpack | <= 1.5 |
References
- http://www.debian.org/security/2002/dsa-141PatchVendor Advisory
- http://www.iss.net/security_center/static/9748.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/5386PatchVendor Advisory
- http://www.debian.org/security/2002/dsa-141PatchVendor Advisory
- http://www.iss.net/security_center/static/9748.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/5386PatchVendor Advisory
FAQ
What is CVE-2002-1425?
CVE-2002-1425 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.
How severe is CVE-2002-1425?
CVE-2002-1425 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1425?
Check the references section above for vendor advisories and patch information. Affected products include: John G. Myers Mpack.