Vulnerabilities > CVE-2023-39136 - Unspecified vulnerability in Ziparchive Project Ziparchive 2.5.4

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
ziparchive-project

Summary

An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.

Vulnerable Configurations

Part Description Count
Application
Ziparchive_Project
1