- Reported
-
- Issued
-
- Package
-
decompress
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#zip-slip
#tar-slip
#path-traversal
#directory-traversal
#arbitrary-file-write
- References
-
- CVSS Score
- 7.1
HIGH
- CVSS Details
-
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- Scope
- Unchanged
- Confidentiality Impact
- None
- Integrity Impact
- High
- Availability Impact
- High
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- Patched
-
no patched versions
- Affected Functions
- Version
decompress::decompress
-
Description
The tar-family extractors in decompress (.tar, .tar.gz, .tar.xz,
.tar.bz2, .tar.zst) build each output path from the raw archive entry path
and write to it with no traversal check, so a malicious archive can write files
outside the destination directory, a "tar-slip" / zip-slip path traversal
(CWE-22 / CWE-23).
In src/decompressors/tar_common.rs (tar_extract):
let filepath = entry.path()?; // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
// strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?; // writes anywhere
.components().skip(opts.strip) removes a fixed number of leading path
components but leaves interior .. components intact so an entry named
e.g. ../../../../home/<user>/.bashrc, or an absolute path, resolves outside
to. This affects all platforms.
Advisory available under CC0-1.0
license.