CVE-2020-23171 log
Source |
|
Severity | High |
Remote | Yes |
Type | Directory traversal |
Description | A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2275 | nim | 1.4.8-1 | High | Vulnerable |
References |
---|
https://github.com/nim-lang/zip/issues/54 |