First published: Tue Sep 24 2024(Updated: )
It was discovered that py7zr was vulnerable to path traversal attacks. If a user or automated system were tricked into extracting a specially crafted 7z archive, an attacker could possibly use this issue to write arbitrary files outside the target directory on the host.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3-py7zr | <0.11.3+dfsg-4ubuntu0.1 | 0.11.3+dfsg-4ubuntu0.1 |
Ubuntu Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.