Description
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-39601 | SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item. |
References
History
Wed, 28 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ziparchive Project
Ziparchive Project ziparchive |
|
| CPEs | cpe:2.3:a:ziparchive_project:ziparchive:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ssziparchive Project
Ssziparchive Project ssziparchive |
Ziparchive Project
Ziparchive Project ziparchive |
Thu, 10 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-04-10T15:56:21.976Z
Reserved: 2022-07-27T00:00:00.000Z
Link: CVE-2022-36943
Updated: 2024-08-03T10:21:31.976Z
Status : Modified
Published: 2023-01-03T21:15:12.757
Modified: 2026-01-28T15:51:44.647
Link: CVE-2022-36943
No data.
OpenCVE Enrichment
No data.
EUVD