CVE-2003-0282

Exp

Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.

Published: 2003-06-16 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2003-0282 is rated High Exploit Risk (63.8/100): CVSS Low severity, with high exploitation likelihood (EPSS 21.13%, 95th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +10.40% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2003-0282

EDB-ID Source Kind Published Link
22584 exploit_db edb 2003-05-10 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2003-0282

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-12-31 10.73% 21.13% +10.40%
2 2025-09-28 12.23% 10.73% -1.50%
3 2025-08-25 12.23%

Full EPSS history (15 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2003-0282

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
2.6 2.0 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:H)
Exploitation requires uncommon or highly specific conditions.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
4.9 2.9 [email protected]

Weakness enumeration for CVE-2003-0282

OS Trackers for CVE-2003-0282

vendor priority summary link
debian not yet assigned CVE-2003-0282 not yet assigned priority: Debian including 1 source packages (unzip), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2003-0282
redhat medium https://access.redhat.com/security/cve/CVE-2003-0282
ubuntu medium CVE-2003-0282 medium priority: Ubuntu including 1 source packages (unzip), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): released 3, needs-triage 1. https://ubuntu.com/security/CVE-2003-0282

Affected software / configurations for CVE-2003-0282

Vendor Product Version Raw CPE
info-zip unzip 5.50 cpe:2.3:a:info-zip:unzip:5.50:*:*:*:*:*:*:*
sco openlinux_server 3.1.1 cpe:2.3:o:sco:openlinux_server:3.1.1:*:*:*:*:*:*:*
sco openlinux_workstation 3.1.1 cpe:2.3:o:sco:openlinux_workstation:3.1.1:*:*:*:*:*:*:*

References for CVE-2003-0282

URL Tags
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txt
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000672
http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-017-01
http://marc.info/?l=bugtraq&m=105259038503175&w=2
http://marc.info/?l=bugtraq&m=105786446329347&w=2
http://www.ciac.org/ciac/bulletins/n-111.shtml
http://www.debian.org/security/2003/dsa-344
http://www.info-zip.org/FAQ.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:073
http://www.redhat.com/support/errata/RHSA-2003-199.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2003-200.html
http://www.securityfocus.com/bid/7550 Exploit Patch Vendor Advisory
http://www.turbolinux.com/security/TLSA-2003-42.txt
https://exchange.xforce.ibmcloud.com/vulnerabilities/12004
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A619
cvelogic Threat Intelligence