CVE-2021-40153
Last modified
CVE-2021-40153 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.. EPSS estimates a 2.50% chance of exploitation in the next 30 days.
Description
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squashfs-Tools Project | Squashfs-Tools | 4.5 |
| Fedoraproject | Fedora | 34 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 8.0 |
| Fedoraproject | Fedora | 33 |
References
- https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790Third Party Advisory
- https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646Patch, Third Party Advisory
- https://github.com/plougher/squashfs-tools/issues/72Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00030.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4967Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790Third Party Advisory
- https://github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646Patch, Third Party Advisory
- https://github.com/plougher/squashfs-tools/issues/72Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00030.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4967Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-40153?
How severe is CVE-2021-40153?
How do I fix CVE-2021-40153?
Are you affected by CVE-2021-40153?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
