CVE-2023-39136
5.5MEDIUMAn unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
게시됨: 8/30/2023업데이트됨: 11/21/2024
설명
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
AI 분석AI 기반
영향받는 제품
ziparchive_projectziparchive
2.5.4
참조
- https://blog.ostorlab.co/zip-packages-exploitation.htmlExploitThird Party Advisory
- https://github.com/ZipArchive/ZipArchive/issues/680ExploitIssue TrackingPatchVendor Advisory
- https://ostorlab.co/vulndb/advisory/OVE-2023-2ExploitThird Party Advisory
- https://security.snyk.io/research/zip-slip-vulnerabilityThird Party Advisory
- https://blog.ostorlab.co/zip-packages-exploitation.htmlExploitThird Party Advisory
- https://github.com/ZipArchive/ZipArchive/issues/680ExploitIssue TrackingPatchVendor Advisory
- https://ostorlab.co/vulndb/advisory/OVE-2023-2ExploitThird Party Advisory
- https://security.snyk.io/research/zip-slip-vulnerabilityThird Party Advisory