SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry ../evil.txt
may be extracted in the parent directory of destFolder
. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.
{ "nvd_published_at": "2022-01-26T21:15:00Z", "cwe_ids": [ "CWE-22" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-02-01T16:20:32Z" }