CVE-2023-39136
5.5MEDIUMAn unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
Veröffentlicht: 8/30/2023Aktualisiert: 11/21/2024
Beschreibung
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
KI-AnalyseKI-gestützt
Betroffene Produkte
ziparchive_projectziparchive
2.5.4
Referenzen
- https://blog.ostorlab.co/zip-packages-exploitation.htmlExploitThird Party Advisory
- https://github.com/ZipArchive/ZipArchive/issues/680ExploitIssue TrackingPatchVendor Advisory
- https://ostorlab.co/vulndb/advisory/OVE-2023-2ExploitThird Party Advisory
- https://security.snyk.io/research/zip-slip-vulnerabilityThird Party Advisory
- https://blog.ostorlab.co/zip-packages-exploitation.htmlExploitThird Party Advisory
- https://github.com/ZipArchive/ZipArchive/issues/680ExploitIssue TrackingPatchVendor Advisory
- https://ostorlab.co/vulndb/advisory/OVE-2023-2ExploitThird Party Advisory
- https://security.snyk.io/research/zip-slip-vulnerabilityThird Party Advisory