SharpZipLib
SharpZipLib (#ziplib, formerly NZipLib) is a compression library for Zip, GZip, BZip2, and Tar written entirely in C# for .NET. It is implemented as an assembly (installable in the GAC), and thus can easily be incorporated into other projects (in any .NET language)
Activity
- Latest release
- 3y ago
- Total releases
- 15
- Cadence
- ~4 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Jan 12, 2011
| Version | Released | |
|---|---|---|
1.4.2
patch
| ||
1.4.1
patch
| ||
1.4.0
minor
| ||
1.3.3
patch
| ||
1.3.2
patch
3 CVEs
CVE-2021-32842
GHSA-mm6g-mmq6-53ff
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that Affected versions
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32841
GHSA-2x7h-96h5-rq84
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced that Affected versions
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.3.1
patch
3 CVEs
CVE-2021-32842
GHSA-mm6g-mmq6-53ff
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that Affected versions
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32841
GHSA-2x7h-96h5-rq84
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced that Affected versions
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.3.0
minor
3 CVEs
CVE-2021-32842
GHSA-mm6g-mmq6-53ff
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that Affected versions
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32841
GHSA-2x7h-96h5-rq84
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced that Affected versions
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2021-32842
GHSA-mm6g-mmq6-53ff
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that Affected versions
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2021-32842
GHSA-mm6g-mmq6-53ff
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that Affected versions
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
CVE-2021-32842
GHSA-mm6g-mmq6-53ff
Feb 01, 2022
Path Traversal in SharpZipLib
4.0
/ 10
Medium
Local
Low
None
None
Unchanged
None
Low
None
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that Affected versions
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References Updated Feb 19, 2024 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.0.0-rc2
pre
1 CVE
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.0.0-rc1
pre
1 CVE
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.0.0-alpha2
pre
2 CVEs
CVE-2018-1002208
GHSA-cqj4-m2pc-v9m5
SNYK-DOTNET-SHARPZIPLIB-60247
May 13, 2022
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
High
None
SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. Affected versions
0.86.0
1.0.0-alpha1
1.0.0-alpha2
Fixed in
1.0.0-rc1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.0.0-alpha1
pre
2 CVEs
CVE-2018-1002208
GHSA-cqj4-m2pc-v9m5
SNYK-DOTNET-SHARPZIPLIB-60247
May 13, 2022
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
High
None
SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. Affected versions
0.86.0
1.0.0-alpha1
1.0.0-alpha2
Fixed in
1.0.0-rc1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.86.0
initial
2 CVEs
CVE-2018-1002208
GHSA-cqj4-m2pc-v9m5
SNYK-DOTNET-SHARPZIPLIB-60247
May 13, 2022
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
High
None
SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. Affected versions
0.86.0
1.0.0-alpha1
1.0.0-alpha2
Fixed in
1.0.0-rc1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-32840
GHSA-m22m-h4rf-pwq3
Feb 01, 2022
Path Traversal in SharpZipLib
7.3
/ 10
High
Local
Low
None
None
Unchanged
Low
High
Low
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry Affected versions
0.86.0
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-rc1
1.0.0-rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
Fixed in
1.3.3
References
Updated Feb 19, 2024 · Source: OSV.dev |