Remix.run Logo
post-it 40 minutes ago

But could an attacker with access to zip tools exploit it to get a root shell? Probably not, but maybe.

cogman10 34 minutes ago | parent | next [-]

Well that's the thing, to build the utilities required extra flags which were pretty rarely enabled. You can, in most distros, ultimately install minizip as a separate package but few do. It's not that useful of a utility. Most people will likely just grab the full blown "zip" application https://infozip.sourceforge.net/Zip.html . Though on linux, even more people are simply using tar with a zlib extension. That's the `tar.gz` files.

PunchyHamster 11 minutes ago | parent | prev [-]

if the tool isn't ran it can't be exploited

CVE should just be far more granular instead of flagging alert for anything using zlib