CVE-2020-23171 log
| Source |
|
| Severity | High |
| Remote | Yes |
| Type | Directory traversal |
| Description | A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2275 | nim | 1.4.8-1 | High | Vulnerable |
| References |
|---|
https://github.com/nim-lang/zip/issues/54 |