QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
{
"binaries": [
{
"binary_version": "0.7.1-1",
"binary_name": "libquazip-dev"
},
{
"binary_version": "0.7.1-1",
"binary_name": "libquazip-headers"
},
{
"binary_version": "0.7.1-1",
"binary_name": "libquazip1"
},
{
"binary_version": "0.7.1-1",
"binary_name": "libquazip5-1"
},
{
"binary_version": "0.7.1-1",
"binary_name": "libquazip5-dev"
},
{
"binary_version": "0.7.1-1",
"binary_name": "libquazip5-headers"
}
]
}
{
"binaries": [
{
"binary_version": "0.7.3-5ubuntu1",
"binary_name": "libquazip-dev"
},
{
"binary_version": "0.7.3-5ubuntu1",
"binary_name": "libquazip-headers"
},
{
"binary_version": "0.7.3-5ubuntu1",
"binary_name": "libquazip1"
},
{
"binary_version": "0.7.3-5ubuntu1",
"binary_name": "libquazip5-1"
},
{
"binary_version": "0.7.3-5ubuntu1",
"binary_name": "libquazip5-dev"
},
{
"binary_version": "0.7.3-5ubuntu1",
"binary_name": "libquazip5-headers"
}
]
}