PT-2021-10849 · Nim-Lang · Nim-Lang

Jiahao42

·

Published

2021-08-10

·

Updated

2021-08-17

·

CVE-2020-23171

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nim-lang versions all
Description A vulnerability allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.
Recommendations For Nim-lang versions all, consider restricting the handling of zip files with dot-slash characters in file names to prevent arbitrary file writing until a patch is available. As a temporary workaround, consider validating and sanitizing zip file contents before processing them.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23171

Affected Products

Nim-Lang