CVE-2023-39138 Information

Description

An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.

Reference

https://github.com/weichsel/ZIPFoundation/issues/282 https://blog.ostorlab.co/zip-packages-exploitation.html https://ostorlab.co/vulndb/advisory/OVE-2023-6 https://ostorlab.co/vulndb/advisory/OVE-2023-4

Share on: