296,746
Total vulnerabilities in the database
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
| Software | From | Fixed in |
|---|---|---|
| rubyzip_project / rubyzip | - | 1.2.1.x |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
| redhat / cloudforms | 4.6 | 4.6.x |
rubyzip
|
- | 1.2.2 |