CVE-2018-1002208Path Traversal in Sharpziplib

CWE-22Path Traversal5 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.6%
top 30.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 25
Latest updateMay 13

Description

SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5sharpziplib/sharpziplib< 1.0 RC1
debiandebian/mono< mono 5.18.0.240+dfsg-1 (bookworm)
Debianmono/mono< 5.18.0.240+dfsg-1+3

Patches

🔴Vulnerability Details

3
GHSA
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib2022-05-13
OSV
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib2022-05-13
OSV
CVE-2018-1002208: SharpZipLib before 12018-07-25

📋Vendor Advisories

1
Debian
CVE-2018-1002208: mono - SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attack...2018