Vulnerability Description
Directory traversal vulnerability in the archive decompression library in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in a compressed archive.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ahnlab | V3 Virusblock 2005 | 6.0.0.383 |
| Ahnlab | V3Net | 6.0.0.383 |
| Ahnlab | V3Pro 2004 | 6.0.0.383 |
References
- http://info.ahnlab.com/english/advisory/01.htmlPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=112680062609377&w=2
- http://secunia.com/advisories/15674/PatchVendor Advisory
- http://secunia.com/secunia_research/2005-17/advisory/PatchVendor Advisory
- http://www.securityfocus.com/bid/14848Patch
- http://info.ahnlab.com/english/advisory/01.htmlPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=112680062609377&w=2
- http://secunia.com/advisories/15674/PatchVendor Advisory
- http://secunia.com/secunia_research/2005-17/advisory/PatchVendor Advisory
- http://www.securityfocus.com/bid/14848Patch
FAQ
What is CVE-2005-3030?
CVE-2005-3030 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in the archive decompression library in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows...
How severe is CVE-2005-3030?
CVE-2005-3030 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3030?
Check the references section above for vendor advisories and patch information. Affected products include: Ahnlab V3 Virusblock 2005, Ahnlab V3Net, Ahnlab V3Pro 2004.