VOOZH about

URL: https://github.com/advisories/GHSA-m22m-h4rf-pwq3

⇱ Path Traversal in SharpZipLib · CVE-2021-32840 · GitHub Advisory Database · GitHub


Skip to content

Path Traversal in SharpZipLib

High severity GitHub Reviewed Published to the GitHub Advisory Database • Updated

Package

SharpZipLib (NuGet)

Affected versions

< 1.3.3

Patched versions

1.3.3

Description

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry ../evil.txt may be extracted in the parent directory of destFolder. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

References

Reviewed
Published to the GitHub Advisory Database
Last updated

Severity

High
/ 10

CVSS v3 base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

EPSS score

(78th percentile)

Weaknesses

CVE ID

CVE-2021-32840

GHSA ID

GHSA-m22m-h4rf-pwq3
See something to contribute? Suggest improvements for this vulnerability.
You can’t perform that action at this time.