Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:3393-1

Опубликовано: 26 сент. 2022
Источник: suse-cvrf

Описание

Security update for libarchive

This update for libarchive fixes the following issues:

  • CVE-2021-23177: Fixed symlink ACL extraction that modifies ACLs of the target system (bsc#1192425).

Список пакетов

Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
libarchive13-3.4.2-150200.4.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
libarchive13-3.4.2-150200.4.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
libarchive13-3.4.2-150200.4.9.1
Image SLES15-SP3-SAPCAL-Azure
libarchive13-3.4.2-150200.4.9.1
Image SLES15-SP3-SAPCAL-EC2-HVM
libarchive13-3.4.2-150200.4.9.1
Image SLES15-SP3-SAPCAL-GCE
libarchive13-3.4.2-150200.4.9.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
libarchive-devel-3.4.2-150200.4.9.1
libarchive13-3.4.2-150200.4.9.1
SUSE Linux Enterprise Module for Development Tools 15 SP3
bsdtar-3.4.2-150200.4.9.1
openSUSE Leap 15.3
bsdtar-3.4.2-150200.4.9.1
libarchive-devel-3.4.2-150200.4.9.1
libarchive13-3.4.2-150200.4.9.1
libarchive13-32bit-3.4.2-150200.4.9.1

Описание

An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.


Затронутые продукты
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:libarchive13-3.4.2-150200.4.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:libarchive13-3.4.2-150200.4.9.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE:libarchive13-3.4.2-150200.4.9.1
Image SLES15-SP3-SAPCAL-Azure:libarchive13-3.4.2-150200.4.9.1

Ссылки