Path Traversal Vulnerability: Write Arbitrary Files via Archive Extraction

CVE-2024-10389
Currently unrated 🤨

Key Information

Vendor
Google
Status
Safearchive
Vendor
CVE Published:
4 November 2024

Summary

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc

Affected Version(s)

Safearchive < 0

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Jan Harrie
.