Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24902
http://www.vupen.com/english/advisories/2006/0730
http://www.securityfocus.com/archive/1/425971/100/0/threaded