Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24972
http://www.securityfocus.com/archive/1/426153/100/0/threaded
http://www.securityfocus.com/archive/1/425967/100/0/threaded