Dzip: Directory traversal vulnerability Dzip is vulnerable to a directory traversal attack. dzip 2005-06-06 2006-05-22 93079 remote 2.9-r1 2.9-r1

Dzip is a compressor and uncompressor especially made for demo recordings of id's Quake.

Dzip is vulnerable to a directory traversal attack when extracting archives.

An attacker could exploit this vulnerability by creating a specially crafted archive to extract files to arbitrary locations.

There is no known workaround at this time.

All Dzip users should upgrade to the latest available version:

# emerge --sync # emerge --ask --oneshot --verbose ">=games-utils/dzip-2.9-r1"
CVE-2005-1874 koon koon DerCorny