Skip to content

Update rubyzip gem#23

Closed
IanHoar wants to merge 1 commit intodevunwired:masterfrom
IanHoar:ianhoar/rubyzip_version
Closed

Update rubyzip gem#23
IanHoar wants to merge 1 commit intodevunwired:masterfrom
IanHoar:ianhoar/rubyzip_version

Conversation

@IanHoar
Copy link
Copy Markdown

@IanHoar IanHoar commented Nov 29, 2018

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem

rubyzip/rubyzip@d07b13a

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem

rubyzip/rubyzip@d07b13a
@devunwired
Copy link
Copy Markdown
Owner

Merged #25 with a newer version.

@devunwired devunwired closed this Sep 27, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants