CVE-2023-39136
5.5MEDIUMAn unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
Publicado: 8/30/2023Atualizado: 11/21/2024
Descrição
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
Análise IADesenvolvido por IA
Produtos Afetados
ziparchive_projectziparchive
2.5.4
Referências
- https://blog.ostorlab.co/zip-packages-exploitation.htmlExploitThird Party Advisory
- https://github.com/ZipArchive/ZipArchive/issues/680ExploitIssue TrackingPatchVendor Advisory
- https://ostorlab.co/vulndb/advisory/OVE-2023-2ExploitThird Party Advisory
- https://security.snyk.io/research/zip-slip-vulnerabilityThird Party Advisory
- https://blog.ostorlab.co/zip-packages-exploitation.htmlExploitThird Party Advisory
- https://github.com/ZipArchive/ZipArchive/issues/680ExploitIssue TrackingPatchVendor Advisory
- https://ostorlab.co/vulndb/advisory/OVE-2023-2ExploitThird Party Advisory
- https://security.snyk.io/research/zip-slip-vulnerabilityThird Party Advisory