Debian Security Advisory 3801-1

Debian Linux Security Advisory 3801-1 – It was discovered that ruby-zip, a Ruby module for reading and writing zip files, is prone to a directory traversal vulnerability. An attacker can take advantage of this flaw to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.

Leave a Reply