Launchpad.net

CVE 2006-0950

unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with ".." (dot dot) sequences in a filename.

See the CVE page on Mitre.org for more details.

References