SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry ../evil.txt may be extracted in the parent directory of destFolder. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.
{
"github_reviewed_at": "2022-02-01T16:20:32Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"nvd_published_at": "2022-01-26T21:15:00Z"
}