A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-15925 | A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/kuba--/zip/issues/123 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T14:58:14.680Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-23172
No data.
Status : Modified
Published: 2021-08-10T17:15:07.043
Modified: 2024-11-21T05:13:37.127
Link: CVE-2020-23172
No data.
OpenCVE Enrichment
No data.
EUVD