Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7556
HistoryOct 02, 2018 - 7:40 a.m.

Arbitrary File Write

2018-10-0207:40:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.001

Percentile

24.7%

zziplib is vulnerable to arbitrary file writes. The library does not properly sanitize file paths, allowing a malicious user to overwrite arbitrary files on the system by passing a zip file with .. in it.