Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7664

Опубликовано: 23 июн. 2020
Источник: debian

Описание

In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-unknwon-caeremovedpackage

Примечания

  • https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMUNKNWONCAEZIP-570383

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

CVSS3: 7.5
nvd
больше 5 лет назад

In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

CVSS3: 7.5
github
больше 4 лет назад

Path Traversal in github.com/unknwon/cae/zip