A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.
{ "binaries": [ { "binary_name": "nim", "binary_version": "0.12.0-2" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-23171.json"
{ "binaries": [ { "binary_name": "nim", "binary_version": "0.17.2-1ubuntu2" } ] }
{ "binaries": [ { "binary_name": "nim", "binary_version": "1.0.6-1" } ] }
{ "binaries": [ { "binary_name": "nim", "binary_version": "1.6.14-1ubuntu2" } ] }
{ "binaries": [ { "binary_name": "nim", "binary_version": "2.2.4-1" } ] }
{ "binaries": [ { "binary_name": "nim", "binary_version": "2.2.4-2" } ] }