—
PYSEC-2022-42998
Quick fix
PYSEC-2022-42998 — py7zr: upgrade to the fixed version with the command below.
pip install --upgrade 'py7zr>=1bb43f17515c7f69673a1c88ab9cc72a7bbef406'Details
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/py7zr
Introduced in:
0Fixed in: 1bb43f17515c7f69673a1c88ab9cc72a7bbef406Fix
pip install --upgrade 'py7zr>=1bb43f17515c7f69673a1c88ab9cc72a7bbef406'References
- https://github.com/miurahr/py7zr/commit/1bb43f17515c7f69673a1c88ab9cc72a7bbef406[FIX]
- http://packetstormsecurity.com/files/170127/py7zr-0.20.0-Directory-Traversal.html[EVIDENCE]
- http://packetstormsecurity.com/files/170127/py7zr-0.20.0-Directory-Traversal.html[WEB]
- http://packetstormsecurity.com/files/170127/py7zr-0.20.0-Directory-Traversal.html[ADVISORY]
- https://lessonsec.com/cve/cve-2022-44900/[EVIDENCE]
- https://lessonsec.com/cve/cve-2022-44900/[WEB]
- https://github.com/advisories/GHSA-m8xw-9x5x-6vh3[ADVISORY]