Bug 1218142 (CVE-2023-6891) - VUL-0: CVE-2023-6891: peazip: uncontrolled search path
Summary: VUL-0: CVE-2023-6891: peazip: uncontrolled search path
Status: NEW
Alias: CVE-2023-6891
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/388475/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-12-18 07:58 UTC by SMASH SMASH
Modified: 2023-12-27 07:36 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-12-18 07:58:59 UTC
A vulnerability has been found in PeaZip 9.4.0 and classified as problematic. Affected by this vulnerability is an unknown functionality in the library dragdropfilesdll.dll of the component Library Handler. The manipulation leads to uncontrolled search path. An attack has to be approached locally. Upgrading to version 9.6.0 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248251. NOTE: Vendor was contacted early, confirmed the existence of the flaw and immediately worked on a patched release.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-6891
Comment 1 Alexander Bergmann 2023-12-18 08:00:49 UTC
openSUSE:Backports:SLE-15-SP5  peazip  v9.0.0
openSUSE:Backports:SLE-15-SP6  peazip  v9.4.0
openSUSE:Factory               peazip  v9.4.0