Bug 1998621 (CVE-2021-40153)
Summary: | CVE-2021-40153 squashfs-tools: unvalidated filepaths allow writing outside of destination | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
Component: | vulnerability | Assignee: | Nobody <nobody> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | adas, bruno, katzj, kyle |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | squashfs-tools 4.5 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in Squashfs-tools, where it is vulnerable to attacks similar to zip-slip. During extraction, a file can escape the destination directory either via the '../' string to access the parent directory or via symlinks. This flaw allows a specially crafted squashfs archive to install or overwrite files outside of the destination directory.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1998622, 2000637, 2000638, 2000656 | ||
Bug Blocks: | 1998293 |
Description
Guilherme de Almeida Suckevicz
2021-08-27 18:20:35 UTC
Created squashfs-tools tracking bugs for this issue: Affects: fedora-all [bug 1998622] FEDORA-2021-cdbd827c1e has been pushed to the Fedora 34 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-2021-9fb6da134f has been pushed to the Fedora 33 stable repository. If problem still persists, please make note of it in this bug report. The fix is now in all current versions of Fedora. This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2396 https://access.redhat.com/errata/RHSA-2024:2396 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:3139 https://access.redhat.com/errata/RHSA-2024:3139 |