PT-2022-26150 · Lancet+1 · Lancet+1

Cokebeer

·

Published

2022-11-17

·

Updated

2022-12-07

·

CVE-2022-41920

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Lancet versions prior to 2.1.10 Lancet versions prior to 1.3.4
Description The issue is a ZipSlip problem that occurs when using the fileutil package to unzip files. This can be exploited when using the fileutil package. No information is provided about the estimated number of potentially affected devices or real-world incidents.
Recommendations For versions prior to 2.1.10, upgrade to version 2.1.10 or above. For versions prior to 1.3.4, upgrade to version 1.3.4 or above. As a temporary workaround, consider avoiding the use of the fileutil package to unzip files until a patch is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-41920
GHSA-PP3F-XRW5-Q5J4
GO-2022-1114

Affected Products

Lancet
Fileutils