SSZipArchive versions 2.5.3 and... CVE-2022-36943

- AV AC AU C I A
发布: 2023-01-03
修订: 2024-11-21

SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息