7.8

CVE-2023-39137

Exploit
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Archive ProjectArchive Version3.3.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.236
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://blog.ostorlab.co/zip-packages-exploitation.html
Exploit
https://github.com/brendan-duncan/archive/issues/266
Issue Tracking
https://ostorlab.co/vulndb/advisory/OVE-2023-3
Exploit
https://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_name_spoofing/
Third Party Advisory