<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:49:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-195168</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-195168</link>
      <description>EUVD-2026-195168</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-195168</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47877</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47877</link>
      <description>&lt;p&gt;Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you&amp;#39;re using the Extractor.FS interface, then upgrading to /v4 will require to implement the new methods that have been added.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you&amp;#39;re using the Extractor.FS interface, then upgrading to /v4 will require to implement the new methods that have been added.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47877</guid>
    </item>
    <item>
      <title>GHSA-8rm2-93mq-jqhc — Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory.</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8rm2-93mq-jqhc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/codeclysm/extract/v3, Go: github.com/codeclysm/extract/v4, Go: github.com/codeclysm/extract&lt;/p&gt;
&lt;p&gt;### Impact
A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory.&lt;/p&gt;
&lt;p&gt;### Patches
Please use version 4.0.0 or later `github.com/codeclysm/extract/v4`. Any previous version is affected by the bug.&lt;/p&gt;
&lt;p&gt;### Workarounds
No knows workarounds.&lt;/p&gt;
&lt;p&gt;### Backward compatibility notes about upgrading to `/v4` from `/v3`&lt;/p&gt;
&lt;p&gt;If you&amp;#39;re not using the `extract.Extractor.FS` interface, you will not face any breaking changes and upgrading should be as simple as changing the import to `/v4`. This should be the case for most of the userbase.&lt;/p&gt;
&lt;p&gt;If you&amp;#39;re using the `Extractor.FS` interface, then upgrading to `/v4` will require to implement the new methods that have been added:&lt;/p&gt;
&lt;p&gt;```go
type FS interface {
    Link(string, string) error
    MkdirAll(string, os.FileMode) error
    OpenFile(name string, flag int, perm os.FileMode) (*os.File, error)
    Symlink(string, string) error&lt;/p&gt;
&lt;p&gt;// The following methods have been added in the /v4 interface:&lt;/p&gt;
&lt;p&gt;Remove(path string) error
    Stat(name string) (os.FileInfo, error)
    Chmod(name string, mode os.FileMode) error
}
```&lt;/p&gt;
&lt;p&gt;There should be no other breaking changes in the `/v4` API.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/codeclysm/extract/v3, Go: github.com/codeclysm/extract/v4, Go: github.com/codeclysm/extract&lt;/p&gt;
&lt;p&gt;### Impact
A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory.&lt;/p&gt;
&lt;p&gt;### Patches
Please use version 4.0.0 or later `github.com/codeclysm/extract/v4`. Any previous version is affected by the bug.&lt;/p&gt;
&lt;p&gt;### Workarounds
No knows workarounds.&lt;/p&gt;
&lt;p&gt;### Backward compatibility notes about upgrading to `/v4` from `/v3`&lt;/p&gt;
&lt;p&gt;If you&amp;#39;re not using the `extract.Extractor.FS` interface, you will not face any breaking changes and upgrading should be as simple as changing the import to `/v4`. This should be the case for most of the userbase.&lt;/p&gt;
&lt;p&gt;If you&amp;#39;re using the `Extractor.FS` interface, then upgrading to `/v4` will require to implement the new methods that have been added:&lt;/p&gt;
&lt;p&gt;```go
type FS interface {
    Link(string, string) error
    MkdirAll(string, os.FileMode) error
    OpenFile(name string, flag int, perm os.FileMode) (*os.File, error)
    Symlink(string, string) error&lt;/p&gt;
&lt;p&gt;// The following methods have been added in the /v4 interface:&lt;/p&gt;
&lt;p&gt;Remove(path string) error
    Stat(name string) (os.FileInfo, error)
    Chmod(name string, mode os.FileMode) error
}
```&lt;/p&gt;
&lt;p&gt;There should be no other breaking changes in the `/v4` API.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8rm2-93mq-jqhc</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3911-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</guid>
    </item>
  </channel>
</rss>
