Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-21633

Опубликовано: 03 янв. 2024
Источник: debian
EPSS Высокий

Описание

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource names which can be manipulated by attacker to place files at desired location on the system Apktool runs on. Affected environments are those in which an attacker may write/overwrite any file that user has write access, and either user name is known or cwd is under user folder. Commit d348c43b24a9de350ff6e5bd610545a10c1fc712 contains a patch for this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apktoolfixed2.7.0+dfsg-7package
apktoolfixed2.7.0+dfsg-6+deb12u1bookwormpackage
apktoolignoredbullseyepackage
apktoolno-dsabusterpackage

Примечания

  • https://github.com/iBotPeaches/Apktool/security/advisories/GHSA-2hqv-2xv4-5h5w

  • https://github.com/iBotPeaches/Apktool/commit/d348c43b24a9de350ff6e5bd610545a10c1fc712

EPSS

Процентиль: 99%
0.73456
Высокий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource names which can be manipulated by attacker to place files at desired location on the system Apktool runs on. Affected environments are those in which an attacker may write/overwrite any file that user has write access, and either user name is known or cwd is under user folder. Commit d348c43b24a9de350ff6e5bd610545a10c1fc712 contains a patch for this issue.

CVSS3: 7.8
nvd
около 2 лет назад

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource names which can be manipulated by attacker to place files at desired location on the system Apktool runs on. Affected environments are those in which an attacker may write/overwrite any file that user has write access, and either user name is known or cwd is under user folder. Commit d348c43b24a9de350ff6e5bd610545a10c1fc712 contains a patch for this issue.

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость инструмента для реверс-инжиниринга APK-файлов Android Apktool, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записать/перезаписать произвольные данные

EPSS

Процентиль: 99%
0.73456
Высокий