Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe...
Vulnerability Description
Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0926
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vupen.com/english/advisories/2006/0732
- http://www.osvdb.org/23463
- http://www.securityfocus.com/bid/16806
- http://www.securityfocus.com/archive/1/425972/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24886
- http://www.hamid.ir/security/stuffit.txt
- http://secunia.com/advisories/19010
Affected Vendor
smithmicro
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.