Directory traversal vulnerability in the doextractcurrentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.
{
"binaries": [
{
"binary_version": "1.1-8",
"binary_name": "libminizip-dev"
},
{
"binary_version": "1.1-8",
"binary_name": "libminizip1"
},
{
"binary_version": "1.1-8",
"binary_name": "libminizip1-dbgsym"
},
{
"binary_version": "1.1-8",
"binary_name": "minizip"
},
{
"binary_version": "1.1-8",
"binary_name": "minizip-dbgsym"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "1.1-8",
"binary_name": "libminizip-dev"
},
{
"binary_version": "1.1-8",
"binary_name": "libminizip1"
},
{
"binary_version": "1.1-8",
"binary_name": "libminizip1-dbgsym"
},
{
"binary_version": "1.1-8",
"binary_name": "minizip"
},
{
"binary_version": "1.1-8",
"binary_name": "minizip-dbgsym"
}
],
"availability": "No subscription required"
}