VendorsZipArchive Projectziparchiveall versions
Vulnerabilities

ZipArchive Project ZipArchive

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2022-36943
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
Published 2023-01-03 · Modified
8.1EPSS 0.009
CVE-2023-39136
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
Published 2023-08-30 · Modified
5.5EPSS 0.004