{"id":"MGASA-2023-0107","summary":"Updated unarj packages fix security vulnerability","details":"Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute\narbitrary code via an arj archive that contains long filenames.\n(CVE-2004-0947)\nDirectory traversal vulnerability in the -x (extract) command line option\nin unarj allows remote attackers to overwrite arbitrary files via an arj\narchive with filenames that contain .. (dot dot) sequences. (CVE-2004-1027)\n","modified":"2026-04-16T04:42:28.810319894Z","published":"2023-03-24T05:55:49Z","upstream":["CVE-2004-0947","CVE-2004-1027"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0107.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31546"}],"affected":[{"package":{"name":"unarj","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/unarj?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.65-6.1.mga8.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0107.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}