adm-zip@0.2.1

Javascript implementation of zip for nodejs with support for electron original-fs. Allows user to create or extract zip files both in memory or to/from disk

  • latest version

    0.6.1

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the adm-zip package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Memory Allocation with Excessive Size Value

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value via the async decompression path in methods/inflater.js, where the decompression size cap enforced by zlib's maxOutputLength option is not applied to the streaming API. An attacker can supply a zip archive whose entries declare a small or zero uncompressed size but contain a large compressed payload (a decompression bomb), causing unbounded memory growth and a crash of the host process. Additionally, a declared size of 0 previously disabled the cap entirely on the synchronous path, allowing the same class of attack through entries that lie about their size.

    How to fix Memory Allocation with Excessive Size Value?

    Upgrade adm-zip to version 0.6.1 or higher.

    <0.6.1
    • H
    Improper Handling of Highly Compressed Data (Data Amplification)

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) via the inflater process. An attacker can exhaust system memory and disrupt service availability by submitting specially crafted ZIP archives with highly compressible entries that declare a zero uncompressed size.

    How to fix Improper Handling of Highly Compressed Data (Data Amplification)?

    Upgrade adm-zip to version 0.6.1 or higher.

    <0.6.1
    • H
    Allocation of Resources Without Limits or Throttling

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in zipEntry.js and entryHeader.js, which size a Buffer.alloc() call directly from the uncompressed-size field of a ZIP central directory header without validating it. An attacker can crash the process with an out-of-memory condition by supplying a small ZIP file, around 120 bytes, whose header declares a roughly 4 GB uncompressed size, triggering the oversized allocation before any CRC check.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade adm-zip to version 0.5.18 or higher.

    <0.5.18
    • H
    Directory Traversal

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Directory Traversal. It could extract files outside the target folder.

    How to fix Directory Traversal?

    Upgrade adm-zip to version 0.5.2 or higher.

    <0.5.2
    • C
    Arbitrary File Write via Archive Extraction (Zip Slip)

    adm-zip is a JavaScript implementation for zip data compression for NodeJS.

    Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip).

    How to fix Arbitrary File Write via Archive Extraction (Zip Slip)?

    Upgrade adm-zip to version 0.4.11 or higher.

    <0.4.11