CVE-2017-1000472
poco - security update
6.5
MEDIUM
CVSS 3.1
EPSS 0.46%
Description
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".
How to fix CVE-2017-1000472
To remediate CVE-2017-1000472, upgrade the affected package to a fixed version below.
- —upgrade to 1.8.0-2 or later
- —upgrade to 1.3.6p1-5+deb8u1 or later
Is CVE-2017-1000472 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.8.0-2
- from 0, < 1.3.6p1-5+deb8u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |