Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frjv-h9wg-233r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

EPSS

Процентиль: 93%
0.09239
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

CVSS3: 5.3
nvd
около 6 лет назад

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

CVSS3: 5.3
debian
около 6 лет назад

cabextract before 1.6 does not properly check for leading slashes when ...

EPSS

Процентиль: 93%
0.09239
Низкий