Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerability report #183

Closed
febinrev opened this issue Nov 2, 2023 · 4 comments
Closed

Security Vulnerability report #183

febinrev opened this issue Nov 2, 2023 · 4 comments

Comments

@febinrev
Copy link

febinrev commented Nov 2, 2023

I am a security researcher, and I have found a security vulnerability in Xarchiver and the vulnerability is capable of Remote Command Execution upon extracting a crafted Archive.

I would like to safely disclose the details about the vulnerability to the devs, please provide me with the right contact information to report the bug.

My Email: febin.sec@gmail.com

Thanks,
Febin

@ib
Copy link
Owner

ib commented Nov 2, 2023

I've enabled private vulnerability reporting for the repository. You should be able to report at https://github.com/ib/xarchiver/security. If it doesn't work, please let me know. I'll have to re-check the configuration for private vulnerability reporting then.

@febinrev
Copy link
Author

febinrev commented Nov 14, 2023

I've enabled private vulnerability reporting for the repository. You should be able to report at https://github.com/ib/xarchiver/security. If it doesn't work, please let me know. I'll have to re-check the configuration for private vulnerability reporting then.

Hey, just reported the vulnerability there.

edit: Sorry for the late response, was busy last week and didn't notice your reply.

ib added a commit that referenced this issue Dec 27, 2023
All cpio versions up to and including 2.12 are vulnerable
to path traversal with maliciously crafted cpio archives.

This closes github issue #183, reported by febinrev.
@ib
Copy link
Owner

ib commented Dec 27, 2023

Fixed. Thank you for reporting.

@ib ib closed this as completed Dec 27, 2023
@febinrev
Copy link
Author

febinrev commented Dec 27, 2023 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants