PT-2018-9627 · Mholt · Archiver

Published

2018-07-25

·

Updated

2024-08-21

·

CVE-2018-1002207

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: mholt/archiver versions before e4ef56d48eb029648b0e895bb0b6a393ef0829c3
Description: The issue allows attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction, also known as 'Zip-Slip'. This can occur when extracting archives, potentially leading to unauthorized file modifications.
Recommendations: For versions before e4ef56d48eb029648b0e895bb0b6a393ef0829c3, update to a version that includes the fix for this issue to prevent arbitrary file writes during archive extraction.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2018-1002207
GHSA-5WMG-J84W-4JJ4
GO-2022-0799
SNYK-GOLANG-GITHUBCOMMHOLTARCHIVERCMDARCHIVER-50071

Affected Products

Archiver