[Japanese] | |
JVNDB-2018-000090 | |
Multiple directory traversal vulnerabilities in AttacheCase | |
Overview | |
AttacheCase is an open source file encryption software provided by HiBARA Software. AttacheCase contains a directory traversal vulnerability (CWE-22) due to a flaw in processing filenames in ATC files. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 3.3 (Low) [IPA Score]
CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
| |
Affected Products | |
| |
HiBARA Software | |
[Updated on August 31, 2018] This advisory was first published on August 6, 2018. At that point it was stated that the affected products were "AttacheCase ver.2.8.3.0 and earlier" and "AttacheCase ver.3.2.3.0 and earlier". However, later on it was found that the updated versions "AttacheCase ver.2.8.4.0" and "AttacheCase ver.3.3.0.0" contained insufficient fixes. Therefore, information under [Products Affected] was modified as of as of August 31, 2018. | |
Impact | |
* Decrypting a crafted ATC file may result in creation of an arbitrary file or overwriting of an existing file - CVE-2018-0659 | |
Solution | |
[Update the Software] | |
Vendor Information | |
HiBARA Software | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2018/08/06 |
Date First Published | 2018/08/06 |
Date Last Updated | 2019/07/25 |