CVE-2006-0950
EPSS 1.7%
Description
unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with ".." (dot dot) sequences in a filename.
How to fix CVE-2006-0950
To remediate CVE-2006-0950, upgrade the affected package to a fixed version below.
- Debian/unalz—upgrade to 0.55-1 or later
Is CVE-2006-0950 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.55-1