zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a …/ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as ‘Zip-Slip’.
CPE | Name | Operator | Version |
---|---|---|---|
zt-zip | eq | zt-zip-1.8 | |
zt-zip | eq | zt-zip-1.12 | |
zt-zip | eq | zt-zip-1.6 | |
zt-zip | eq | zt-zip-1.3 | |
zt-zip | eq | zt-zip-1.7 | |
zt-zip | eq | zt-zip-1.2 | |
zt-zip | eq | zt-zip-1.10 | |
zt-zip | eq | zt-zip-1.9 | |
zt-zip | eq | zt-zip-1.0 | |
zt-zip | eq | zt-zip-1.4 |