Back

MEDIUM

zt-zip: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file

Published Jul 25, 2018

Description

zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jul 25, 2018
Updated Sep 16, 2024
Reserved Jul 25, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 5, 2018
GHSA-QCF3-9VMH-XW4R