CVE-2020-23171

Name
CVE-2020-23171
Description
A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/nim-lang/zip/issues/54

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:nim-lang:nim-lang:*:*:*:*:*:*:*:* nim-lang == None == None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status