ALAS2-2018-1043


Amazon Linux 2 Security Advisory: ALAS-2018-1043
Advisory Release Date: 2018-06-20 19:57 Pacific
Advisory Updated Date: 2018-07-24 21:16 Pacific
Severity: Important

Issue Overview:

A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names. A remote attacker could use this vulnerability to write files outside the target directory and overwrite existing files with malicious code or vulnerable configurations.(CVE-2018-1002200)


Affected Packages:

plexus-archiver


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update plexus-archiver to update your system.

New Packages:
noarch:
    plexus-archiver-2.4.2-5.amzn2.noarch
    plexus-archiver-javadoc-2.4.2-5.amzn2.noarch

src:
    plexus-archiver-2.4.2-5.amzn2.src