[Bug 15336] New: unzip security issue

bugzilla at busybox.net bugzilla at busybox.net
Tue Feb 14 10:27:05 UTC 2023


https://bugs.busybox.net/show_bug.cgi?id=15336

            Bug ID: 15336
           Summary: unzip security issue
           Product: Busybox
           Version: 1.35.x
          Hardware: All
                OS: Linux
            Status: NEW
          Severity: normal
          Priority: P5
         Component: Other
          Assignee: unassigned at busybox.net
          Reporter: nimrod.stoler at cyberark.com
                CC: busybox-cvs at busybox.net
  Target Milestone: ---

Hello,

During our review of an embedded product we discovered that we can escalate our
privileges using busybox’s unzip utility.

We kindly like to disclose the specifics to you or to anyone dealing with
security on your side.

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the busybox-cvs mailing list