VDB
Sign up
CRITICAL9.8

GHSA-xhg6-9j5j-w4vf

DotNetZip Directory Traversal vulnerability

Quick fix

GHSA-xhg6-9j5j-w4vf — ProDotNetZip: upgrade to the fixed version with the command below.

dotnet add package ProDotNetZip --version 1.19.0

Details

Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetZip
Introduced in: 1.10.1

No fixed version published yet for DotNetZip (nuget). Pin to a known-safe version or switch to an alternative.

NuGet/ProDotNetZip
Introduced in: 0Fixed in: 1.19.0
Fixdotnet add package ProDotNetZip --version 1.19.0

References