CVE-2019-10743
MEDIUMArchiver < 3.3.2 - Path Traversal
Title source: ruleDescription
All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a "../../file.exe" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily.
Exploits (1)
References (4)
Scores
CVSS v3
5.5
EPSS
0.0124
EPSS Percentile
79.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (2)
archiver_project/archiver
3.0.0 - 3.3.2
mholt/archiver
3.0.0 - 3.3.2Go
Published
Oct 29, 2019
Tracked Since
Feb 18, 2026