OSV 1.4.0 · unreviewed · 修改于 2022-02-05 08:00
发布时间
2022-02-01 08:00
GitHub 审查时间
—
NVD 发布时间
2022-01-31 19:15
源文件
advisories/unreviewed/2022/02/GHSA-qpj6-xj62-7c95/GHSA-qpj6-xj62-7c95.json
The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a ZipFile object.
该公告没有提供结构化的受影响软件包信息。