VDB

GCVE-110-MAGEIA-2024-19

GCVE-110-MAGEIA-2024-19
Advisory Published
Vulnetix · Advisory published January 30, 2024
Updated zlib packages fix a security vulnerability: Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.

Affected Products

VendorProductVersionsPlatforms
Mageiazlib0 (affected), 1.2.13-1.2.mga9 (unaffected), 0 (affected), 1.2.13-1.2.mga9 (unaffected)
Mageiaopencpn-sar-plugin0 (affected), 4.0.0-2.mga9 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›