Description
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1085 | SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3. |
Github GHSA |
GHSA-m22m-h4rf-pwq3 | Path Traversal in SharpZipLib |
References
History
Tue, 22 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T18:32:29.435Z
Reserved: 2021-05-12T00:00:00.000Z
Link: CVE-2021-32840
Updated: 2024-08-03T23:33:56.092Z
Status : Modified
Published: 2022-01-26T21:15:13.097
Modified: 2024-11-21T06:07:51.583
Link: CVE-2021-32840
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA