Bug 1591449 - (CVE-2018-10860) CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180628,repor...
: Security
Depends On: 1596131 1596132 1596133 1596134 1596135
Blocks: 1588762
  Show dependency treegraph
 
Reported: 2018-06-14 14:19 EDT by Cedric Buissart
Modified: 2018-07-19 14:05 EDT (History)
17 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Github redhotpenguin/perl-Archive-Zip/pull/33 None None None 2018-06-28 09:16 EDT

  None (edit)
Description Cedric Buissart 2018-06-14 14:19:34 EDT
Archive::Zip does not protect against symlinks or '..' path traversals. Attacks similar to CVE-2007-4829 or CVE-2018-12015 also affect Archive::Zip.
Comment 1 Petr Pisar 2018-06-15 02:10:51 EDT
Archive::Zip has never been part of upstream Perl release:

$ corelist Archive::Zip

Data for 2018-04-14
Archive::Zip was not in CORE (or so I think)

It's an independent project <https://metacpan.org/release/Archive-Zip>.
Comment 2 Cedric Buissart 2018-06-15 06:10:20 EDT
Note: summary edited for clarification.
Comment 4 Cedric Buissart 2018-06-20 09:09:21 EDT
Acknowledgments:

Name: Doran Moppert (Red Hat)
Comment 7 Cedric Buissart 2018-06-28 05:56:47 EDT
Created perl-Archive-Zip tracking bugs for this issue:

Affects: fedora-all [bug 1596132]
Comment 10 Cedric Buissart 2018-06-29 07:55:02 EDT
Upstream fix:
https://github.com/redhotpenguin/perl-Archive-Zip/commit/95e1df86327
Comment 11 Fedora Update System 2018-07-19 13:47:29 EDT
perl-Archive-Zip-1.59-6.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.
Comment 12 Fedora Update System 2018-07-19 14:05:27 EDT
perl-Archive-Zip-1.60-3.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.