Amazon Linux 2 Security Advisory: ALAS-2018-1043
Advisory Release Date: 2018-06-20 19:57 Pacific
Advisory Updated Date: 2018-07-24 21:16 Pacific
A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names. A remote attacker could use this vulnerability to write files outside the target directory and overwrite existing files with malicious code or vulnerable configurations.(CVE-2018-1002200)
Affected Packages:
plexus-archiver
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update plexus-archiver to update your system.
noarch:
plexus-archiver-2.4.2-5.amzn2.noarch
plexus-archiver-javadoc-2.4.2-5.amzn2.noarch
src:
plexus-archiver-2.4.2-5.amzn2.src