Skip to content

Commit 0ff419e

Browse files
severinkaelinreedloden
authored andcommitted
Add patched version for CVE-2018-1000544 (#347)
1 parent b84fda3 commit 0ff419e

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

gems/rubyzip/CVE-2018-1000544.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@ description: |
1010
If a site allows uploading of .zip files, an attacker can upload a malicious file
1111
which contains symlinks or files with absolute pathnames "../" to write arbitrary
1212
files to the filesystem.
13+
patched_versions:
14+
- ">= 1.2.2"
1315
related:
1416
cve:
1517
- 2017-5946

0 commit comments

Comments
 (0)