ZeroHour

CVE-2022-36943

PoC
CVSS 3.1
8.1 high
EPSS
<1%p55
Published
()
Modified
Description

SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.

Vendors
ziparchive project
Products
ziparchive
Weakness
CWE-22, CWE-59
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.