CVE-2023-6891: PeaZip Library dragdropfilesdll.dll uncontrolled search path
A vulnerability has been found in PeaZip 9.4.0 and classified as problematic. Affected by this vulnerability is an unknown functionality in the library dragdropfilesdll.dll of the component Library Handler. The manipulation leads to uncontrolled search path. An attack has to be approached locally. Upgrading to version 9.6.0 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248251. NOTE: Vendor was contacted early, confirmed the existence of the flaw and immediately worked on a patched release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6891?
CVE-2023-6891 is classified as a problematic vulnerability affecting PeaZip 9.4.0.
How do I fix CVE-2023-6891?
To fix CVE-2023-6891, it is recommended to update PeaZip to the latest version available.
What component is affected by CVE-2023-6891?
CVE-2023-6891 affects the dragdropfilesdll.dll component of PeaZip.
What kind of vulnerability is CVE-2023-6891?
CVE-2023-6891 involves an uncontrolled search path vulnerability.
Which version of PeaZip is vulnerable to CVE-2023-6891?
PeaZip version 9.4.0 is the version that is vulnerable to CVE-2023-6891.