- Reported
-
- Issued
-
- Package
-
unzip
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#zip-slip
#path-traversal
#directory-traversal
#arbitrary-file-write
#zip
- References
-
- Patched
-
no patched versions
- Affected Functions
- Version
unzip::Unzipper::unzip
-
Description
Summary
Unzipper::unzip extracts each archive entry to a path built from the entry's
raw, attacker-controlled name without any traversal check. A ZIP archive whose
entry names contain ../ components (or an absolute path) can therefore cause
files to be written outside the destination directory chosen by the caller —
a "zip-slip" / directory-traversal arbitrary file write (CWE-22 / CWE-23 /
CWE-36).
Affected versions
All published versions are affected. unzip has only ever released 0.1.0
(published 2017-12-23) and appears unmaintained, so no fixed version is
available.
Proof of concept
A malicious archive with a single entry named ../ESCAPED.txt extracted via
Unzipper::unzip writes ESCAPED.txt one level above the destination directory.
Advisory available under CC0-1.0
license.