CVE-2022-35410
Summary
| CVE | CVE-2022-35410 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-08 18:15:00 UTC |
| Updated | 2022-07-20 17:29:00 UTC |
| Description | mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5185-1 mat2 |
DEBIAN |
www.debian.org |
|
| mat2 0.13.0 |
MISC |
dustri.org |
|
| Arbitrary read via malicious zip file (#174) · Issues · jvoisin / mat2 · GitLab |
MISC |
0xacab.org |
|
| Prevent arbitrary file read via zip archives (beebca4b) · Commits · jvoisin / mat2 · GitLab |
MISC |
0xacab.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180892 Debian Security Update for mat2 (DSA 5185-1)
- 184190 Debian Security Update for mat2 (CVE-2022-35410)
- 690896 Free Berkeley Software Distribution (FreeBSD) Security Update for mat2 (830855f3-ffcc-11ec-9d41-d05099c8b5a7)