Описание
Path traversal in Archive
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-39139
- https://github.com/brendan-duncan/archive/issues/265
- https://github.com/brendan-duncan/archive/commit/6de492385d72af044231c4163dff13a43d991c83
- https://github.com/brendan-duncan/archive/commit/edb0d480733a44d28ff3d5e4e2779153ba645ce7
- https://blog.ostorlab.co/zip-packages-exploitation.html
- https://ostorlab.co/vulndb/advisory/OVE-2023-5
Пакеты
Наименование
archive
Затронутые версииВерсия исправления
<= 3.3.7
3.3.8
Связанные уязвимости
CVSS3: 7.8
nvd
больше 2 лет назад
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.