Zip Slip: a sneaky way to install malware using zip and other packing utilities
by Cory Doctorow from on (#3RRZS)
Packing files into archives like zips, tars, jars, wars, cpios, apks, rars and 7zs is a common way to keep important files and filesystem structures together when sharing them; it's also a source of potentially dangerous malware attacks. (more")