9.8
CVSSv3

CVE-2021-32840

Published: 26/01/2022 Updated: 07/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sharpziplib project sharpziplib

Vendor Advisories

SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library Prior to version 133, a TAR file entry `/eviltxt` may be extracted in the parent directory of `destFolder` This leads to arbitrary file write that may lead to code execution The vulnerability was patched in version 133 (CVE-2021-32840) ...