MEDIUM5.3CVE-2015-9275ARC 5.21q allows directory traversal via a full pathname in an archive file.
from 0, < 5.21q-6
—CVE-2005-2992arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerab…