weichsel / ZIPFoundation

Effortless ZIP Handling in Swift
MIT License
2.31k stars 255 forks source link

Vulnerability : An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file #303

Closed jainricha closed 9 months ago

jainricha commented 9 months ago

Summary

Blackduck scan reports the below security issue: An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.

Is there any expected timeline by when this can be expected to fix? or If there is already a fix available for this.

Please suggest.

weichsel commented 9 months ago

Closing because this is a duplicate of https://github.com/weichsel/ZIPFoundation/issues/281 and https://github.com/weichsel/ZIPFoundation/issues/282.