Bug 2235824 (CVE-2023-39810) - CVE-2023-39810 busybox: CPIO command of Busybox allows attackers to execute a directory traversal
Summary: CVE-2023-39810 busybox: CPIO command of Busybox allows attackers to execute a...
Keywords:
Status: NEW
Alias: CVE-2023-39810
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2235825
TreeView+ depends on / blocked
 
Reported: 2023-08-29 20:19 UTC by Anten Skrabec
Modified: 2023-09-18 06:06 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the BusyBox tool. This issue occurs in the cpio command of BusyBox and may allow attackers to execute a directory traversal. If untrusted archives are extracted, this can result in files written outside of the destination directory or files being overwritten that contain configuration in the form of shell scripts such as ~/.bashrc or scripts that enable login from a remote side such as the ~/.ssh/authorized_keys file.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Anten Skrabec 2023-08-29 20:19:41 UTC
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.

https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/
http://busybox.com


Note You need to log in before you can comment on or make changes to this bug.