説明
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
AI分析AIによる分析
影響を受ける製品
ziparchive_projectziparchive
2.5.4
参照
- https://blog.ostorlab.co/zip-packages-exploitation.htmlExploitThird Party Advisory
- https://github.com/ZipArchive/ZipArchive/issues/680ExploitIssue TrackingPatchVendor Advisory
- https://ostorlab.co/vulndb/advisory/OVE-2023-2ExploitThird Party Advisory
- https://security.snyk.io/research/zip-slip-vulnerabilityThird Party Advisory
- https://blog.ostorlab.co/zip-packages-exploitation.htmlExploitThird Party Advisory
- https://github.com/ZipArchive/ZipArchive/issues/680ExploitIssue TrackingPatchVendor Advisory
- https://ostorlab.co/vulndb/advisory/OVE-2023-2ExploitThird Party Advisory
- https://security.snyk.io/research/zip-slip-vulnerabilityThird Party Advisory