Lucene search

K
cvelistFacebookCVELIST:CVE-2022-36943
HistoryJan 03, 2023 - 12:00 a.m.

CVE-2022-36943

2023-01-0300:00:00
CWE-22
facebook
www.cve.org
2
ssziparchive
arbitrary file write
vulnerability
symlinks
cve-2022-36943

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

39.4%

SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.

CNA Affected

[
  {
    "vendor": "ZipArchive",
    "product": "SSZipArchive",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "2.5.3",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

39.4%

Related for CVELIST:CVE-2022-36943