Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jan Harrie

#37103of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2024-16238
7.5
2024-11-04
Unknown · Safearchive · CVE-2024-10389
**Name of the Vulnerable Software and Affected Versions** Safearchive versions prior to commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc **Description** The issue is related to a Path Traversal vulnerability in Safearchive on platforms with case-insensitive filesystems, such as NTFS. This vulnerability allows attackers to write arbitrary files via archive extraction containing symbolic links. **Recommendations** For versions prior to commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc, upgrade past this commit to resolve the issue. As a temporary workaround, consider restricting the use of archive extraction containing symbolic links until a patch is available.