Notre sélection d'alertes et avis SSI.
Sources : US Cert, Cert EU, Cert FR, Cnil, VulDB.

mardi 26 janvier 2021

ORAS up to 0.8.x ZIP path traversal

A vulnerability classified as critical was found in ORAS up to 0.8.x. This vulnerability affects an unknown code of the component ZIP Handler. Upgrading to version 9.0.0 eliminates this vulnerability. The upgrade is hosted for download at github.com. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.

Lien vers l'article source

Auteur: VulDB

Catégories: VulDBNombre de vues: 71

x

Événements SSI