Beveiligingsadvies

CVE-2021-32840

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-01-26 21:05:10
Laatst bijgewerkt 2025-04-22 18:32:29
Toegewezen door GitHub_M
CVSS-score 7.3
Status PUBLISHED

Beschrijving

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.