CVE-2019-16511
Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../ sequence) is concatenated with the…
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../ sequence) is concatenated with the destination path.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- firegiant/wix toolset
- Source
- cve@mitre.org
References
- https://github.com/GitHubAssessments/CVE_Assessments_09_2019
- https://github.com/wixtoolset/issues/issues/6075Patch, Third Party Advisory
- https://wixtoolset.org/development/wips/6075-dtf-zip-slip/Third Party Advisory
- https://www.firegiant.com/blog/2019/9/18/wix-v3.11.2-released/Patch, Vendor Advisory
- https://github.com/GitHubAssessments/CVE_Assessments_09_2019
- https://github.com/wixtoolset/issues/issues/6075Patch, Third Party Advisory
- https://wixtoolset.org/development/wips/6075-dtf-zip-slip/Third Party Advisory
- https://www.firegiant.com/blog/2019/9/18/wix-v3.11.2-released/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.