Security Advisories (1)
CVE-2018-10860 (2018-06-28)

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.

NAME

Archive::Zip::Tree - (DEPRECATED) methods for adding/extracting trees using Archive::Zip

DESCRIPTION

This module is deprecated, because all its methods were moved into the main Archive::Zip module.

It is included in the distribution merely to avoid breaking old code.

See Archive::Zip.

AUTHOR

Ned Konz, perl@bike-nomad.com

COPYRIGHT

Copyright (c) 2000-2002 Ned Konz. All rights reserved. This program is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

SEE ALSO

Archive::Zip