CVE-2019-10743
Summary
| CVE | CVE-2019-10743 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-29 19:15:00 UTC |
| Updated | 2024-02-02 02:13:00 UTC |
| Description | All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a "../../file.exe" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Page not found | Snyk |
|
snyk.io |
|
| Invalid vulnerability |
MISC |
snyk.io |
Not Applicable |
| Prevent arbitrary file overwrite via path traversal [CVE-2019-10743] by giuliocomi · Pull Request #169 · mholt/archiver · GitHub |
MISC |
github.com |
Third Party Advisory |
| Zip Slip Vulnerability | Snyk |
MISC |
snyk.io |
Third Party Advisory |
| Arbitrary File Write via Archive Extraction (Zip Slip) in github.com/mholt/archiver/cmd/arc | Snyk |
MISC |
snyk.io |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983830 Go (go) Security Update for github.com/mholt/archiver/cmd/arc (GHSA-h74j-692g-48mq)