Vulnerability Description
util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Grin | Grin | < 1.0.2 |
Related Weaknesses (CWE)
References
- https://github.com/mimblewimble/grin/pull/2624PatchThird Party Advisory
- https://github.com/mimblewimble/grin/releases/tag/v1.0.2Release NotesThird Party Advisory
- https://www.grin-forum.org/t/critical-vulnerability-in-grin-1-0-1-and-older-fixeExploitIssue TrackingThird Party Advisory
- https://github.com/mimblewimble/grin/pull/2624PatchThird Party Advisory
- https://github.com/mimblewimble/grin/releases/tag/v1.0.2Release NotesThird Party Advisory
- https://www.grin-forum.org/t/critical-vulnerability-in-grin-1-0-1-and-older-fixeExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2019-9195?
CVE-2019-9195 is a vulnerability with a CVSS score of 9.8 (CRITICAL). util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.
How severe is CVE-2019-9195?
CVE-2019-9195 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-9195?
Check the references section above for vendor advisories and patch information. Affected products include: Grin Grin.