VDB
Sign up
MEDIUM5.5

GHSA-cqj4-m2pc-v9m5

Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib

Quick fix

GHSA-cqj4-m2pc-v9m5 — SharpZipLib: upgrade to the fixed version with the command below.

dotnet add package SharpZipLib --version 1.0.0-rc1

Details

SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/SharpZipLib
Introduced in: 0Fixed in: 1.0.0-rc1
Fixdotnet add package SharpZipLib --version 1.0.0-rc1

References