HTTP: Allegra unzipFileIntoDirectory Directory Traversal

This signature detects attempts to exploit a known vulnerability against Allegra. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the implementation of the extractFileFromZip method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26524.

Short Name
HTTP:DIR:ALLEGRA-UNZIP-FILEINTO
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Allegra CVE-2025-3485 Directory Traversal unzipFileIntoDirectory
Release Date
06/20/2025
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3819
False Positive
Unknown

Found a potential security threat?