Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m22m-h4rf-pwq3

Опубликовано: 01 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Path Traversal in SharpZipLib

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry ../evil.txt may be extracted in the parent directory of destFolder. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

Пакеты

Наименование

SharpZipLib

nuget
Затронутые версииВерсия исправления

< 1.3.3

1.3.3

EPSS

Процентиль: 81%
0.01545
Низкий

7.3 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 4 лет назад

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

CVSS3: 7.3
nvd
около 4 лет назад

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

CVSS3: 7.3
debian
около 4 лет назад

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior ...

EPSS

Процентиль: 81%
0.01545
Низкий

7.3 High

CVSS3

Дефекты

CWE-22