Arbitrary File Write in adm-zip
Moderate severity
GitHub Reviewed
Published
Jul 27, 2018
to the GitHub Advisory Database
•
Updated Sep 12, 2023
Description
Published to the GitHub Advisory Database
Jul 27, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 12, 2023
Versions of
adm-zip
before 0.4.9 are vulnerable to arbitrary file write when used to extract a specifically crafted archive that contains path traversal filenames (../../file.txt
for example).Recommendation
Update to version 0.4.9 or later.
References