• py7zr 0.20.0 Directory Traversal

    From Security Bot@2:250/1 to All on Thu Feb 23 08:22:00 2023


    py7zr 0.20.0 Directory Traversal

    A directory traversal vulnerability in the SevenZipFile.extractall()
    function of the python library py7zr versions 0.20.0 and earlier allows attackers to read arbitrary files on the local machine via a malicious 7z
    file extraction.

    https://packetstormsecurity.com/files/170127/py7zr0200-traversal.txt

    Wed, 07 Dec 2022 14:47:20 GMT
    ________________________________
    --- The information is for inforamtional purposes only.
    * Origin: Read us with http://winpoint.org JID: rs@captflint.com