py7zr 0.20.0 Directory Traversal

Discussion in 'News Aggregator' started by Packet Storm, 8 Dec 2022.

  1. Packet Storm

    Packet Storm Guest

    A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr versions 0.20.0 and earlier allows attackers to read arbitrary files on the local machine via a malicious 7z file extraction.

    Continue reading...
     

Share This Page

Loading...