Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed.
| Software | From | Fixed in |
|---|---|---|
| gnu / gnump3d | 2.9 | 2.9.x |
| gnu / gnump3d | 2.9.5 | 2.9.5.x |
| gnu / gnump3d | 2.9.2 | 2.9.2.x |
| gnu / gnump3d | 2.9.4 | 2.9.4.x |
| gnu / gnump3d | 2.9.3 | 2.9.3.x |
| gnu / gnump3d | 2.9.1 | 2.9.1.x |