util / src / zip.rs in Grin prima 1.0.2 strapazza file sospetti. Un utente malintenzionato può eseguire codice arbitrario tramite directory traversal in un archivio ZIP.
https://github.com/mimblewimble/grin/pull/2624
https://github.com/mimblewimble/grin/releases/tag/v1.0.2
https://www.grin-forum.org/t/critical-vulnerability-in-grin-1-0-1-and-older-fixed-in-1-0-2/4343
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9195