Описание
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| busybox | fixed | 1:1.37.0-7 | package | |
| busybox | no-dsa | trixie | package | |
| busybox | no-dsa | bookworm | package | |
| busybox | postponed | bullseye | package | |
| busybox | postponed | buster | package |
Примечания
https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/
https://bugs.busybox.net/show_bug.cgi?id=16033
Fixed by: https://git.busybox.net/busybox/commit/?id=9a8796436b9b0641e13480811902ea2ac57881d3
Связанные уязвимости
CVSS3: 7.8
ubuntu
больше 2 лет назад
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
CVSS3: 7.3
redhat
больше 2 лет назад
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
CVSS3: 7.8
nvd
больше 2 лет назад
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
CVSS3: 7.8
github
больше 2 лет назад
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.