Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-21706

Опубликовано: 04 окт. 2021
Источник: debian
EPSS Низкий

Описание

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.0not-affectedpackage
php7.4not-affectedpackage
php7.3not-affectedpackage
php7.0not-affectedpackage

Примечания

  • Fixed in 8.0.11, 7.4.24, 7.3.31

  • PHP Bug: https://bugs.php.net/81420

EPSS

Процентиль: 56%
0.00346
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 4 года назад

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.

CVSS3: 5.3
nvd
почти 4 года назад

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.

github
около 3 лет назад

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.

CVSS3: 5.3
fstec
почти 4 года назад

Уязвимость функции ZipArchive::extractTo интерпретатора PHP, позволяющая нарушителю создать или перезаписать файлы

suse-cvrf
больше 2 лет назад

Security update for php7

EPSS

Процентиль: 56%
0.00346
Низкий