CVE-2004-1027 describes a directory traversal vulnerability in the unarj utility, specifically when using the -x (extract) command line option. This flaw allows remote attackers to overwrite arbitrary files on affected systems, including various distributions of Linux and the unarj software itself, by crafting ARJ archives containing filenames with ".." sequences. The vulnerability carries a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network with low attack complexity and requires no authentication, leading to a potential impact of partial data integrity compromise. Despite its age, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei. The CVE has received minimal community discussion and media coverage, suggesting a low level of public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.62CPE matchmatch criteria | cpe:2.3:a:arjsoftware:unarj:2.62:*:*:*:*:*:*:* | ||
2.63CPE matchmatch criteria | cpe:2.3:a:arjsoftware:unarj:2.63:a:*:*:*:*:*:* | ||
2.64CPE matchmatch criteria | cpe:2.3:a:arjsoftware:unarj:2.64:*:*:*:*:*:*:* | ||
2.65CPE matchmatch criteria | cpe:2.3:a:arjsoftware:unarj:2.65:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.