CVE-2018-10860: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 43.4% chance of exploitation in the next 30 days.
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
- Debian Debian Linux: version 8.0 only
- Perl-Archive-Zip Project Perl-Archive-Zip: affected versions not specified
Published 2018-06-29. Last modified 2026-06-17.