{ "id": "CVE-2023-39137", "sourceIdentifier": "cve@mitre.org", "published": "2023-08-30T22:15:09.030", "lastModified": "2023-08-31T10:02:10.690", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing." } ], "metrics": {}, "references": [ { "url": "https://blog.ostorlab.co/zip-packages-exploitation.html", "source": "cve@mitre.org" }, { "url": "https://github.com/brendan-duncan/archive/issues/266", "source": "cve@mitre.org" }, { "url": "https://ostorlab.co/vulndb/advisory/OVE-2023-3", "source": "cve@mitre.org" }, { "url": "https://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_name_spoofing/", "source": "cve@mitre.org" } ] }