CVE-2019-16511
Summary
| CVE | CVE-2019-16511 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-19 16:15:00 UTC |
| Updated | 2019-11-04 18:15:00 UTC |
| Description | An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../ sequence) is concatenated with the destination path. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Firegiant | Wix Toolset | All | All | All | All |
| Application | Firegiant | Wix Toolset | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WiX v3.11.2 released | MISC | www.firegiant.com | Patch, Vendor Advisory |
| DTF vulnerable to "Zip Slip" · Issue #6075 · wixtoolset/issues · GitHub | MISC | github.com | Patch, Third Party Advisory |
| GitHub - GitHubAssessments/CVE_Assessments_09_2019: Enpass | MISC | github.com | |
| DTF vulnerable to "Zip Slip" | MISC | wixtoolset.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.