Ouch · Ouch · CVE-2024-13941
**Name of the Vulnerable Software and Affected Versions**
ouch-org ouch versions up to 0.3.1
**Description**
A critical issue has been found, affecting the function `ouch::archive::zip::convert zip date time` of the file `zip.rs`. The manipulation of the argument `month` leads to memory corruption. The attack must be approached locally.
**Recommendations**
Upgrading to version 0.4.0 is able to address this issue.
It is recommended to upgrade the affected component.