VDB
Sign up
MEDIUM5.5

GHSA-7378-6268-4278

DotNetZip Zip-Slip Vulnerability

Quick fix

GHSA-7378-6268-4278 — DotNetZip: upgrade to the fixed version with the command below.

dotnet add package DotNetZip --version 1.11.0

Details

DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetZip
Introduced in: 0Fixed in: 1.11.0
Fixdotnet add package DotNetZip --version 1.11.0

References