CVE-2015-2060: Cabextract Project Cabextract
Medium severity, CVSS 5.3. EPSS: 2.3% chance of exploitation in the next 30 days.
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
Affected products
- Cabextract Project Cabextract: before 1.6 (fixed in 1.6)
Published 2019-11-29. Last modified 2026-06-17.