CVE-2022-36943
PoC —CVSS 3.1
8.1 high
EPSS
<1%p55
Published
()
Modified
Description
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
- Vendors
- ziparchive project
- Products
- ziparchive
- Weakness
- CWE-22, CWE-59
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.