logo

Database

Lack of data validation - Path Traversal In adm-zip

Description

Arbitrary File Write in adm-zip Versions of adm-zip before 0.4.9 are vulnerable to arbitrary file write when used to extract a specifically crafted archive that contains path traversal filenames (../../file.txt for example).

Recommendation

Update to version 0.4.9 or later.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-9K6S4 – Vulnerability | Fluid Attacks Database