Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-30571

Опубликовано: 29 мая 2023
Источник: debian
EPSS Низкий

Описание

Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libarchiveunfixedpackage

Примечания

  • https://github.com/libarchive/libarchive/issues/1876

  • libarchive does not officially support multi-threaded use archive_read_disk

  • and archive_write_disk API functions. Upstream aims to clarify the documentation:

  • https://github.com/libarchive/libarchive/issues/1876#issuecomment-1627767567

  • We'll use the first version to include the documentation update as fixed version

EPSS

Процентиль: 1%
0.00013
Низкий

Связанные уязвимости

CVSS3: 3.9
ubuntu
около 2 лет назад

Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.

CVSS3: 5.3
redhat
около 2 лет назад

Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.

CVSS3: 3.9
nvd
около 2 лет назад

Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.

CVSS3: 5.3
redos
почти 2 года назад

Уязвимость Libarchive

CVSS3: 3.9
github
около 2 лет назад

Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.

EPSS

Процентиль: 1%
0.00013
Низкий