Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-1408
http://www.securityfocus.com/bid/5386