CVE-2003-0282 is a directory traversal vulnerability in UnZip 5.50, affecting various Info-ZIP and SCO OpenLinux products. Attackers can exploit this by crafting archives with invalid characters between two dot characters, which are then filtered to create a ".." sequence, allowing arbitrary file overwrites. With a CVSS score of 2.6 (AV:N/AC:H/Au:N/C:N/I:P/A:N), it has a low severity, requiring high attack complexity and resulting in partial integrity impact. While not in CISA's KEV catalog, an ExploitDB entry exists, and the vulnerability has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.50CPE matchmatch criteria | cpe:2.3:a:info-zip:unzip:5.50:*:*:*:*:*:*:* | ||
3.1.1CPE matchmatch criteria | cpe:2.3:o:sco:openlinux_server:3.1.1:*:*:*:*:*:*:* | ||
3.1.1CPE matchmatch criteria | cpe:2.3:o:sco:openlinux_workstation:3.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.