← Back

Go Rpm Utils

go_rpm_utils

Vendor: Sas • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sas
1Go Rpm Utils
Nov 21, 2024
Jun 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction...Show more
In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction outside of the current directory. Note: the fixing commit was applied to all affected versions which were re-released.Show less