Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppwj-pqwg-cmvw

Опубликовано: 31 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory. This issue affects yaffshiv up to version 0.1 included, which is the most recent at time of publication.

A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory. This issue affects yaffshiv up to version 0.1 included, which is the most recent at time of publication.

EPSS

Процентиль: 55%
0.0032
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
nvd
около 3 лет назад

A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory. This issue affects yaffshiv up to version 0.1 included, which is the most recent at time of publication.

EPSS

Процентиль: 55%
0.0032
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22