Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1002208

Опубликовано: 25 июл. 2018
Источник: debian

Описание

SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
monofixed5.18.0.240+dfsg-1package
monono-dsastretchpackage
monono-dsajessiepackage
mono-reference-assembliesunfixedpackage

Примечания

  • https://snyk.io/vuln/SNYK-DOTNET-SHARPZIPLIB-60247

  • https://github.com/icsharpcode/SharpZipLib/issues/232

  • https://github.com/mono/mono/issues/11492

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 5.5
nvd
больше 7 лет назад

SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS3: 5.5
github
больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib