CVE-2021-41072
Last modified
CVE-2021-41072 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.. EPSS estimates a 2.14% chance of exploitation in the next 30 days.
Description
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a filesystem can cause unsquashfs to first create the symbolic link pointing outside the expected directory, and then the subsequent write operation will cause the unsquashfs process to write through the symbolic link elsewhere in the filesystem.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squashfs-Tools Project | Squashfs-Tools | 4.5 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Debian | Debian Linux | 11.0 |
References
- https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bdPatch, Third Party Advisory
- https://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00017.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4987Third Party Advisory
- https://github.com/plougher/squashfs-tools/commit/e0485802ec72996c20026da320650d8362f555bdPatch, Third Party Advisory
- https://github.com/plougher/squashfs-tools/issues/72#issuecomment-913833405Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00017.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4987Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41072?
How severe is CVE-2021-41072?
How do I fix CVE-2021-41072?
Are you affected by CVE-2021-41072?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
