First published: Tue Dec 27 2022(Updated: )
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
Credit: security@golang.org security@golang.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unzip Project Unzip | <1.0.3-0.20200308084313-2adbaa4891b9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-36561 is critical, with a severity value of 9.1.
CVE-2020-36561 can allow malicious archives containing relative file paths to write or overwrite files outside of the target directory.
The software affected by CVE-2020-36561 is Unzip Project Unzip version 1.0.3-0.20200308084313-2adbaa4891b9.
To fix CVE-2020-36561, update the affected software to version 1.0.3-0.20200308084313-2adbaa4891b9.
You can find more information about CVE-2020-36561 at the following references: [Link 1](https://nvd.nist.gov/vuln/detail/CVE-2020-36561), [Link 2](https://github.com/yi-ge/unzip/pull/1), [Link 3](https://github.com/yi-ge/unzip/commit/2adbaa4891b9690853ef10216189189f5ad7dc73).