PT-2025-45412 · Archive · Archive

CVE-2025-64346

·

Publicado

2025-03-28

·

Atualizado

2025-11-07

CVSS v4.0

6.0

Média

VetorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions archives version 1.0.0
Description archives is a Go library used for extracting archives such as tar and zip files. Version 1.0.0 does not adequately prevent a malicious user from providing a specially crafted archive that could lead to Remote Code Execution (RCE), file modification, or other harmful actions. The severity of the issue depends on the user's permissions, the environment, and how arbitrary archives are handled. The issue arises from improper limitation of a pathname to a restricted directory, allowing for potential path traversal.
Recommendations Update to version 1.0.1 or later.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-64346
GHSA-J95M-RCJP-Q69H
GO-2025-3581

Produtos afetados

Archive