VYPR
Medium severity5.5NVD Advisory· Published Sep 19, 2019· Updated Jun 17, 2026

CVE-2019-16511

CVE-2019-16511

Description

An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../ sequence) is concatenated with the destination path.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:firegiant:wix_toolset:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:firegiant:wix_toolset:*:*:*:*:*:*:*:*range: <3.11.2
    • (no CPE)range: <3.11.2
  • FireGiant/WiX Toolsetdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.