CVE-2018-1002208, also known as 'Zip-Slip', is a directory traversal vulnerability affecting SharpZipLib before version 1.0 RC1. This flaw allows an attacker to write arbitrary files to a system by crafting a malicious Zip archive containing entries with "../" (dot dot slash) sequences. The vulnerability has a CVSS score of 5.5 (Medium) and requires user interaction (UI:R), as the victim must extract the malicious archive. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.86.0.518CPE matchmatch criteria | cpe:2.3:a:sharpziplib_project:sharpziplib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.