Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-40153

Опубликовано: 27 авг. 2021
Источник: debian
EPSS Низкий

Описание

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squashfs-toolsfixed1:4.5-1experimentalpackage
squashfs-toolsfixed1:4.5-2package

Примечания

  • https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790

  • https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646 (4.5)

  • https://github.com/plougher/squashfs-tools/issues/72

EPSS

Процентиль: 65%
0.00496
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 4 года назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CVSS3: 8.1
redhat
почти 6 лет назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CVSS3: 8.1
nvd
почти 4 года назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CVSS3: 8.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 8.1
github
около 3 лет назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

EPSS

Процентиль: 65%
0.00496
Низкий