Описание
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
A flaw was found in OCaml opam. A malicious package containing a crafted .install field with directory traversal sequences allows an attacker to write files to arbitrary locations, potentially overwriting system files and causing arbitrary code execution.
Отчет
To exploit this flaw, an attacker must convince a user to install a malicious package with a specially crafted .install field. Due to this reason, this vulnerability has been rated with an important severity.
Меры по смягчению последствий
To mitigate this vulnerability, do not install packages from untrusted sources and manually inspect the .install field in the package source to make sure it does not contain malicious paths.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | ocaml-dune | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
In OCaml opam before 2.5.1, a .install field containing a destination ...
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
EPSS
7.1 High
CVSS3