QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
{
"binaries": [
{
"binary_name": "libquazip-dev",
"binary_version": "0.7.1-1"
},
{
"binary_name": "libquazip-headers",
"binary_version": "0.7.1-1"
},
{
"binary_name": "libquazip1",
"binary_version": "0.7.1-1"
},
{
"binary_name": "libquazip5-1",
"binary_version": "0.7.1-1"
},
{
"binary_name": "libquazip5-dev",
"binary_version": "0.7.1-1"
},
{
"binary_name": "libquazip5-headers",
"binary_version": "0.7.1-1"
}
]
}
{
"binaries": [
{
"binary_name": "libquazip-dev",
"binary_version": "0.7.3-5ubuntu1"
},
{
"binary_name": "libquazip-headers",
"binary_version": "0.7.3-5ubuntu1"
},
{
"binary_name": "libquazip1",
"binary_version": "0.7.3-5ubuntu1"
},
{
"binary_name": "libquazip5-1",
"binary_version": "0.7.3-5ubuntu1"
},
{
"binary_name": "libquazip5-dev",
"binary_version": "0.7.3-5ubuntu1"
},
{
"binary_name": "libquazip5-headers",
"binary_version": "0.7.3-5ubuntu1"
}
]
}