Vulnerabilities
Vulnerable Software
Ziparchive Project:  >> Ziparchive  Security Vulnerabilities
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
CVSS Score
5.5
EPSS Score
0.001
Published
2023-08-30
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
CVSS Score
8.1
EPSS Score
0.005
Published
2023-01-03


Contact Us

Shodan ® - All rights reserved