CVE-2024-47877

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-47877
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47877.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-47877
Aliases
Related
Published
2024-10-11T17:15:04Z
Modified
2024-10-16T02:27:17.399969Z
Summary
[none]
Details

Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to implement the new methods that have been added.

References

Affected packages

Git / github.com/codeclysm/extract

Affected ranges

Type
GIT
Repo
https://github.com/codeclysm/extract
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

v1

v1.*

v1.0.1
v1.1.0
v1.1.1

v2.*

v2.0.0
v2.1.0
v2.1.1
v2.2.0

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1