CVE-2002-1425
mpack - buffer overflow
EPSS 1.9%
Description
Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.
How to fix CVE-2002-1425
To remediate CVE-2002-1425, upgrade the affected package to a fixed version below.
- Debian/mpack—upgrade to 1.5-9 or later
- Debian/mpack—upgrade to 1.5-7woody2 or later
Is CVE-2002-1425 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.5-9
- from 0, < 1.5-7woody2