5
CVSSv2

CVE-2020-7664

Published: 23/06/2020 Updated: 21/12/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an malicious user to add or replace files system-wide.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

compression and archive extensions project compression and archive extensions zip project

Vendor Advisories

Debian Bug report logs - #967955 golang-github-unknwon-cae: CVE-2020-7664 Package: src:golang-github-unknwon-cae; Maintainer for src:golang-github-unknwon-cae is QA Group <packages@qadebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 5 Aug 2020 20:15:01 UTC Severity: grave Tags: security, ...