Back to search
CVE-2021-40153
Published: Aug 27, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2021-cdbd827c1e
vendor-advisory
DSA-4967
vendor-advisory
FEDORA-2021-9fb6da134f
vendor-advisory
GLSA-202305-29
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now