Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jan Harrie

#38513of 56,337
7.5Total CVSS
Vulnerabilities · 1
PT-2024-16238
7.5
2024-11-04
Unknown · Safearchive · CVE-2024-10389
**Name of the Vulnerable Software and Affected Versions** Safearchive versions prior to commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc **Description** The issue is related to a Path Traversal vulnerability in Safearchive on platforms with case-insensitive filesystems, such as NTFS. This vulnerability allows attackers to write arbitrary files via archive extraction containing symbolic links. **Recommendations** For versions prior to commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc, upgrade past this commit to resolve the issue. As a temporary workaround, consider restricting the use of archive extraction containing symbolic links until a patch is available.