ALAS2-2018-1043


Amazon Linux 2 Security Advisory: ALAS-2018-1043
Advisory Release Date: 2018-07-24 21:16 Pacific
Severity: Important
References: CVE-2018-1002200 

Issue Overview:

A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names. A remote attacker could use this vulnerability to write files outside the target directory and overwrite existing files with malicious code or vulnerable configurations.(CVE-2018-1002200 )


Affected Packages:

plexus-archiver


Issue Correction:
Run yum update plexus-archiver to update your system.

New Packages:
noarch:
    plexus-archiver-2.4.2-5.amzn2.noarch
    plexus-archiver-javadoc-2.4.2-5.amzn2.noarch

src:
    plexus-archiver-2.4.2-5.amzn2.src