CVE-2017-5946: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Rubyzip Project Rubyzip: before 1.2.1 (fixed in 1.2.1)

Published 2017-02-27. Last modified 2026-06-17.