{"id":"GHSA-h74j-692g-48mq","summary":"Path Traversal in MHolt Archiver","details":"All versions of archiver allow attacker to perform a Zip Slip attack via the \"unarchive\" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a \"../../file.exe\" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily.\n\n### Specific Go Packages Affected\ngithub.com/mholt/archiver/cmd/arc","aliases":["CVE-2019-10743"],"modified":"2025-01-14T07:56:51.026896Z","published":"2021-05-18T15:31:53Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-05-17T21:21:43Z","nvd_published_at":"2019-10-29T19:15:16Z","cwe_ids":["CWE-22","CWE-29"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10743"},{"type":"WEB","url":"https://github.com/mholt/archiver/pull/169"},{"type":"WEB","url":"https://github.com/mholt/archiver/pull/203"},{"type":"WEB","url":"https://github.com/mholt/archiver/commit/8217ed3a206c0473b4ec1aff51375b398838073a"},{"type":"WEB","url":"https://github.com/snyk/zip-slip-vulnerability"},{"type":"WEB","url":"https://snyk.io/research/zip-slip-vulnerability"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMMHOLTARCHIVERCMDARC-174728"}],"affected":[{"package":{"name":"github.com/mholt/archiver","ecosystem":"Go","purl":"pkg:golang/github.com/mholt/archiver"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-h74j-692g-48mq/GHSA-h74j-692g-48mq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}