Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-32840

Опубликовано: 26 янв. 2022
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 7.3

Описание

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry ../evil.txt may be extracted in the parent directory of destFolder. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

needs-triage

esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-infra-legacy/trusty

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
impish

not-affected

code not present

Показывать по

7.5 High

CVSS2

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
около 4 лет назад

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

CVSS3: 7.3
debian
около 4 лет назад

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior ...

CVSS3: 7.3
github
около 4 лет назад

Path Traversal in SharpZipLib

7.5 High

CVSS2

7.3 High

CVSS3