VDB
Sign up
MEDIUM5.5

GHSA-h74j-692g-48mq

Path Traversal in MHolt Archiver

Quick fix

GHSA-h74j-692g-48mq — github.com/mholt/archiver: upgrade to the fixed version with the command below.

go get github.com/mholt/archiver@v3.3.2

Details

All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a "../../file.exe" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily.

### Specific Go Packages Affected github.com/mholt/archiver/cmd/arc

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/mholt/archiver
Introduced in: 3.0.0Fixed in: 3.3.2
Fixgo get github.com/mholt/archiver@v3.3.2

References