CVE Vulnerabilities

CVE-2004-1027

Published: Mar 01, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.

Affected Software

NameVendorStart VersionEnd Version
UnarjArjsoftware2.62 (including)2.62 (including)
UnarjArjsoftware2.63-a (including)2.63-a (including)
UnarjArjsoftware2.64 (including)2.64 (including)
UnarjArjsoftware2.65 (including)2.65 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*

References