diff options
author | Martin Wilke <miwi@FreeBSD.org> | 2011-11-14 03:25:46 +0000 |
---|---|---|
committer | Martin Wilke <miwi@FreeBSD.org> | 2011-11-14 03:25:46 +0000 |
commit | 5eeef2311f34b11cd14c114b8ab6aad7c9c28f0f (patch) | |
tree | ae2af1de6f959132751be3694efda162d36ea989 | |
parent | 2cf3c9948fd70a784aa3b36f7c1ec4b0ad71494b (diff) | |
download | ports-5eeef2311f34b11cd14c114b8ab6aad7c9c28f0f.tar.gz ports-5eeef2311f34b11cd14c114b8ab6aad7c9c28f0f.zip |
Notes
-rw-r--r-- | security/vuxml/vuln.xml | 16 |
1 files changed, 8 insertions, 8 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index b4212397bf1f..093897f659ef 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -47,14 +47,14 @@ Note: Please add new entries to the beginning of this file. <p>Tim Brown from Nth Dimention reports:</p> <blockquote cite="http://seclists.org/fulldisclosure/2011/Oct/351"> <p>I recently discovered that the Ark archiving tool is - vulnerable to directory traversal via malformed. When - attempts are made to view files within the malformed Zip - file in Ark's default view, the wrong file may be displayed - due to incorrect construction of the temporary file name. - Whilst this does not allow the wrong file to be overwritten, - after closing the default view, Ark will then attempt to - delete the temporary file which could result in the deletion - of the incorrect file.</p> + vulnerable to directory traversal via malformed. When + attempts are made to view files within the malformed Zip + file in Ark's default view, the wrong file may be displayed + due to incorrect construction of the temporary file name. + Whilst this does not allow the wrong file to be overwritten, + after closing the default view, Ark will then attempt to + delete the temporary file which could result in the deletion + of the incorrect file.</p> </blockquote> </body> </description> |