Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-40153

Опубликовано: 10 сент. 2019
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

A flaw was found in Squashfs-tools, where it is vulnerable to attacks similar to zip-slip. During extraction, a file can escape the destination directory either via the '../' string to access the parent directory or via symlinks. This flaw allows a specially crafted squashfs archive to install or overwrite files outside of the destination directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squashfs-toolsOut of support scope
Red Hat Enterprise Linux 7squashfs-toolsWill not fix
Red Hat Enterprise Linux 8squashfs-toolsFixedRHSA-2024:313922.05.2024
Red Hat Enterprise Linux 9squashfs-toolsFixedRHSA-2024:239630.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1998621squashfs-tools: unvalidated filepaths allow writing outside of destination

EPSS

Процентиль: 65%
0.00496
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 4 года назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CVSS3: 8.1
nvd
почти 4 года назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

CVSS3: 8.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 8.1
debian
почти 4 года назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the file ...

CVSS3: 8.1
github
около 3 лет назад

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.

EPSS

Процентиль: 65%
0.00496
Низкий

8.1 High

CVSS3