Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40153

Опубликовано: 27 авг. 2021
Источник: nvd
CVSS3: 8.1
CVSS2: 5.8
EPSS Низкий

Описание

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squashfs-tools_project:squashfs-tools:4.5:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Конфигурация 5
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00496
Низкий

8.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 4 года назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CVSS3: 8.1
redhat
почти 6 лет назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CVSS3: 8.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 8.1
debian
почти 4 года назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the file ...

CVSS3: 8.1
github
около 3 лет назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

EPSS

Процентиль: 65%
0.00496
Низкий

8.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-22