VDB
Sign up
MEDIUM4.0

GHSA-2x7h-96h5-rq84

Path Traversal in SharpZipLib

Quick fix

GHSA-2x7h-96h5-rq84 — SharpZipLib: upgrade to the fixed version with the command below.

dotnet add package SharpZipLib --version 1.3.3

Details

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced that `destDir` ends with slash. If the `destDir` is not slash terminated like `/home/user/dir` it is possible to create a file with a name thats begins with the destination directory, i.e. `/home/user/dir.sh`. Because of the file name and destination directory constraints, the arbitrary file creation impact is limited and depends on the use case. Version 1.3.3 contains a patch for this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/SharpZipLib
Introduced in: 1.3.0Fixed in: 1.3.3
Fixdotnet add package SharpZipLib --version 1.3.3

References