CVE-2022-36943

S

SZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.

Configurations

Configuration 1 (hide)

cpe:2.3:a:ziparchive_project:ziparchive:*:*:*:*:*:*:*:*

History

28 Jan 2026, 15:51

Type Values Removed Values Added
CPE cpe:2.3:a:ssziparchive_project:ssziparchive:*:*:*:*:*:*:*:* cpe:2.3:a:ziparchive_project:ziparchive:*:*:*:*:*:*:*:*
First Time Ziparchive Project
Ziparchive Project ziparchive

21 Nov 2024, 07:14

Type Values Removed Values Added
References () https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-vgvw-6xcf-qqfc - Exploit, Third Party Advisory () https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-vgvw-6xcf-qqfc - Exploit, Third Party Advisory

Information

Published : 2023-01-03 21:15

Updated : 2026-01-28 15:51


NVD link : CVE-2022-36943

Mitre link : CVE-2022-36943

CVE.ORG link : CVE-2022-36943


JSON object : View

Products Affected
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-59

Improper Link Resolution Before File Access ('Link Following')