Search Results (Refine Search)
- Keyword (text search): cpe:2.3:a:archiver_project:archiver:3.0.1:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2019-10743 |
All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a "../../file.exe" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily. Published: October 29, 2019; 3:15:16 PM -0400 |
V4.0:(not available) V3.1: 5.5 MEDIUM V2.0: 5.8 MEDIUM |