adm-zip@0.1.9

Javascript implementation of zip for nodejs with support for electron original-fs. Allows user to create or extract zip files both in memory or to/from disk

  • latest version

    0.6.1

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    21 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the adm-zip package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Allocation of Resources Without Limits or Throttling

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the async decompression path in methods/inflater.js, where the maxOutputLength cap enforced by zlib's sync API is not applied to the streaming (async) path. An attacker can supply a ZIP entry whose declared uncompressed size is small but whose compressed payload expands arbitrarily, causing unbounded memory growth and crashing the host process.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade adm-zip to version 0.6.1 or higher.

    <0.6.1
    • H
    Incorrect Permission Assignment for Critical Resource

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource via the fileAttr getter in headers/entryHeader.js, which preserves attacker-controlled Unix special permission bits (setuid 0o4000, setgid 0o2000, and sticky 0o1000) from ZIP archive metadata during extraction. When the keepOriginalPermission option is used and extraction is performed as root, an attacker who controls the ZIP archive can plant a setuid-root binary, achieving local privilege escalation.

    Note: This is only exploitable when extraction is performed as a privileged user (e.g., root) with the keepOriginalPermission option enabled.

    How to fix Incorrect Permission Assignment for Critical Resource?

    Upgrade adm-zip to version 0.6.1 or higher.

    <0.6.1
    • H
    Uncaught Exception

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Uncaught Exception via inflateAsync in methods/inflater.js when processing a ZIP entry containing malformed DEFLATE data. The zlib.createInflateRaw stream emits an error event (e.g. Z_DATA_ERROR) that has no registered listener, causing Node.js to re-throw it as an uncaught exception on a later tick and crash the host process.

    How to fix Uncaught Exception?

    Upgrade adm-zip to version 0.6.1 or higher.

    <0.6.1
    • H
    Incorrect Behavior Order

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Incorrect Behavior Order via duplicate entry names in a ZIP archive processed by zipFile.js. Because adm-zip stores all entries in entryList (used by extractAllTo()) but only the last occurrence of a name in entryTable (used by getEntry()), an attacker can supply an archive containing two entries with the same name. An application that validates entry content by calling getEntry() before extracting will inspect one file, while extractAllTo() writes a different file to disk, allowing the attacker to bypass content validation and land arbitrary content on the filesystem.

    How to fix Incorrect Behavior Order?

    Upgrade adm-zip to version 0.6.1 or higher.

    <0.6.1
    • H
    Memory Allocation with Excessive Size Value

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value via the async decompression path in methods/inflater.js, where the decompression size cap enforced by zlib's maxOutputLength option is not applied to the streaming API. An attacker can supply a zip archive whose entries declare a small or zero uncompressed size but contain a large compressed payload (a decompression bomb), causing unbounded memory growth and a crash of the host process. Additionally, a declared size of 0 previously disabled the cap entirely on the synchronous path, allowing the same class of attack through entries that lie about their size.

    How to fix Memory Allocation with Excessive Size Value?

    Upgrade adm-zip to version 0.6.1 or higher.

    <0.6.1
    • H
    Improper Handling of Highly Compressed Data (Data Amplification)

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) via the inflater process. An attacker can exhaust system memory and disrupt service availability by submitting specially crafted ZIP archives with highly compressible entries that declare a zero uncompressed size.

    How to fix Improper Handling of Highly Compressed Data (Data Amplification)?

    Upgrade adm-zip to version 0.6.1 or higher.

    <0.6.1
    • H
    Allocation of Resources Without Limits or Throttling

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in zipEntry.js and entryHeader.js, which size a Buffer.alloc() call directly from the uncompressed-size field of a ZIP central directory header without validating it. An attacker can crash the process with an out-of-memory condition by supplying a small ZIP file, around 120 bytes, whose header declares a roughly 4 GB uncompressed size, triggering the oversized allocation before any CRC check.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade adm-zip to version 0.5.18 or higher.

    <0.5.18
    • H
    Directory Traversal

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Directory Traversal. It could extract files outside the target folder.

    How to fix Directory Traversal?

    Upgrade adm-zip to version 0.5.2 or higher.

    <0.5.2
    • C
    Arbitrary File Write via Archive Extraction (Zip Slip)

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip).

    How to fix Arbitrary File Write via Archive Extraction (Zip Slip)?

    Upgrade adm-zip to version 0.4.11 or higher.

    <0.4.11