Bugzilla – Bug 1191314
VUL-1: CVE-2021-21706: php: ZipArchive:extractTo may be tricked into writing a file outside target directory when extracting a ZIP files
Last modified: 2021-10-05 09:08:09 UTC
CVE-2021-21706 In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-21706 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21706 http://www.cvedetails.com/cve/CVE-2021-21706/ https://bugs.php.net/bug.php?id=81420
Close as invalid.